#BUFFETLINE
Malware/Tool
2020-02-14 • MAR-10271944-3.v1 – North Korean Trojan: BUFFETLINE
BUFFETLINE is a full-featured 32-bit Windows beaconing implant attributed by U.S. government agencies to North Korean HIDDEN COBRA activity and detected as a NukeSped variant. It dynamically resolves APIs from obfuscated strings and contains hardcoded command-and-control addresses. The implant authenticates sessions with PolarSSL, then encodes network traffic through a FakeTLS scheme using a modified RC4 algorithm. Its operator can upload, download, delete, and execute files, open Windows command-line access, create or terminate processes, and enumerate the compromised system.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days