#HappyDoor
Malware/Tool
HappyDoor is a VMP-protected Windows backdoor used by the Kimsuky group in espionage-oriented attacks against South Korean targets. One observed campaign distributed it through a malicious executable masquerading as a Bandizip installer; running the package also installed the legitimate application while launching malicious DLLs and remote scripts through regsvr32 and mshta. Reported capabilities include collecting system and user information, keylogging, screenshots, audio, documents, and files from removable devices, communicating with command-and-control servers, and downloading remote malicious scripts. Campaign components also used PowerShell and VBScript, registry and alternate-data-stream concealment, scheduled tasks for persistence, and cleanup scripts.
-
6
Tagged Reports
-
4
Unique Authors
-
688
Active Days