#CROWDEDFLOUNDER

Malware/Tool

2020-02-14 • MAR-10265965-3.v1 – North Korean Trojan: CROWDEDFLOUNDER

CROWDEDFLOUNDER is a Themida-packed, 32-bit Windows remote-access Trojan attributed by U.S. government agencies to North Korean HIDDEN COBRA activity. It unpacks and executes its RAT component in memory, modifies Windows Firewall rules, and can operate as a listening proxy or connect outward to a command-and-control server. The malware uses rotating XOR to protect communications, collects system, storage, and process information, and can download malicious DLLs and inject them into remote processes. Command-line arguments select a listening port or a remote host and port.

Tagged Reports

« Back