#BUFFETLINE

Malware/Tool

2020-02-14 • MAR-10271944-3.v1 – North Korean Trojan: BUFFETLINE

BUFFETLINE is a full-featured 32-bit Windows beaconing implant attributed by U.S. government agencies to North Korean HIDDEN COBRA activity and detected as a NukeSped variant. It dynamically resolves APIs from obfuscated strings and contains hardcoded command-and-control addresses. The implant authenticates sessions with PolarSSL, then encodes network traffic through a FakeTLS scheme using a modified RC4 algorithm. Its operator can upload, download, delete, and execute files, open Windows command-line access, create or terminate processes, and enumerate the compromised system.

Tagged Reports

« Back