#HttpTroy

Malware/Tool

2015-11-20 • Tracing the Lineage of DarkSeoul

HttpTroy is a Windows backdoor associated with Kimsuky and delivered in observed incidents through spearphishing emails disguised as personal or business documents. It supports file upload and download, screenshot capture, command execution under a specified user context, in-memory module execution, a reverse shell, working-directory changes, waiting, and self-deletion. In an intrusion against a South Korean groupware vendor, an employee workstation infected with an HttpTroy variant was used to install additional tooling, including DWAgent and a yamux-based proxy, after which the attackers downloaded further malware from command-and-control infrastructure. MITRE ATT&CK S9007.

Tagged Reports

« Back