#KANDYKORN
Malware/Tool
2023-11-01 • Elastic catches DPRK passing out KANDYKORN
Known infections began with social engineering that induced victims to download a ZIP archive and run a malicious Python script. A five-stage chain used additional Python scripts and the SUGARLOADER downloader-loader before delivering KANDYKORN; another report notes that the chain hijacked the host's installed Discord application. The backdoor uses a custom network protocol and provides a broad set of post-compromise capabilities, including functionality supporting lateral movement. Later activity linked RustBucket-style droppers with delivery of KANDYKORN payloads, showing overlap between previously distinct macOS campaign chains.
-
8
Tagged Reports
-
6
Unique Authors
-
338
Active Days