#Durian

Malware/Tool

2024-05-09 • APT trends report Q1 2024

Durian is a Golang-based backdoor deployed in focused attacks against two South Korean cryptocurrency-sector victims in August and November 2023. A legitimate program retrieved an initial installer from attacker infrastructure; the installer then created a later-stage loader and registered it as a Windows service for persistence before delivering Durian. Operators used the backdoor to introduce AppleSeed and deployed ngrok, Chrome Remote Desktop, and a custom proxy for continued access, ultimately stealing browser cookies and login credentials. The activity was attributed with high confidence to Kimsuky.

Tagged Reports

« Back