#KANDYKORN

Malware/Tool

2023-11-01 • Elastic catches DPRK passing out KANDYKORN

Known infections began with social engineering that induced victims to download a ZIP archive and run a malicious Python script. A five-stage chain used additional Python scripts and the SUGARLOADER downloader-loader before delivering KANDYKORN; another report notes that the chain hijacked the host's installed Discord application. The backdoor uses a custom network protocol and provides a broad set of post-compromise capabilities, including functionality supporting lateral movement. Later activity linked RustBucket-style droppers with delivery of KANDYKORN payloads, showing overlap between previously distinct macOS campaign chains.

Tagged Reports

« Back