#HttpTroy

Malware/Tool

2025-10-30 • DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant

HttpTroy is a Windows backdoor associated with Kimsuky and delivered in observed incidents through spearphishing emails disguised as personal or business documents. It supports file upload and download, screenshot capture, command execution under a specified user context, in-memory module execution, a reverse shell, working-directory changes, waiting, and self-deletion. In an intrusion against a South Korean groupware vendor, an employee workstation infected with an HttpTroy variant was used to install additional tooling, including DWAgent and a yamux-based proxy, after which the attackers downloaded further malware from command-and-control infrastructure. MITRE ATT&CK S9007.

Tagged Reports

« Back