#DAVESHELL

Malware/Tool

2022-09-14 • It's Time to PuTTY! DPRK Job Opportunity Phishing via WhatsApp

DAVESHELL is publicly available shellcode that functions as an in-memory dropper. In the UNC4034 infection chain, a malicious DLL decrypted and executed DAVESHELL, which mapped and ran an embedded VMProtect-packed AIRDRY.V2 backdoor payload in memory.

Tagged Reports

« Back