#Fullhouse

Malware/Tool

2024-09-09 • Threat Assessment: North Korean Threat Groups

Fullhouse is an HTTP backdoor written in C or C++ and associated with Slow Pisces. It was observed in a supply-chain attack and delivered as a first-stage backdoor. Its supported behavior includes executing arbitrary commands and delivering additional second-stage backdoors to compromised systems. Disassembly of a sample showed unimplemented functions, including one named MyFunctionStealthCodeArea, and code that retrieved the SHELL environment variable through getenv.

Tagged Reports

« Back