#Endoor

Malware/Tool

2024-03-19 • 국내 공공기관의 설치 파일을 위장한 악성코드 (Kimsuky 그룹)

Endoor is a Go-based Windows backdoor used by Kimsuky in operations focused on South Korean targets. Observed forms include a DLL and an executable loader that decrypts and loads the backdoor in memory. A dropper masquerading as an installer from a South Korean public institution extracts and runs Endoor, while earlier activity paired it with the spear-phishing-delivered Nikidoor. The backdoor creates a victim identifier from the hostname, username, and administrator status, establishes persistence through a scheduled task, contacts a command-and-control server for instructions, and has been used to download additional malware, including screenshot-capture tooling.

Tagged Reports

« Back