#Durian
Malware/Tool
2024-05-09 • APT trends report Q1 2024
Durian is a Golang-based backdoor deployed in focused attacks against two South Korean cryptocurrency-sector victims in August and November 2023. A legitimate program retrieved an initial installer from attacker infrastructure; the installer then created a later-stage loader and registered it as a Windows service for persistence before delivering Durian. Operators used the backdoor to introduce AppleSeed and deployed ngrok, Chrome Remote Desktop, and a custom proxy for continued access, ultimately stealing browser cookies and login credentials. The activity was attributed with high confidence to Kimsuky.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days