#LightHand
Malware/Tool
2024-07-25 • Onyx Sleet uses array of malware to gather intelligence for North Korea
LightHand is a custom lightweight Windows backdoor used by Onyx Sleet to maintain remote access to targeted devices. It can launch cmd.exe for arbitrary command execution, query storage information, list directory contents, and create or delete files. These functions give operators basic shell and filesystem control after compromise without deploying a larger remote-access framework. Microsoft documented LightHand alongside TigerRAT, SmallTiger, and ValidAlpha in campaigns directed at South Korean defense organizations, placing it within Onyx Sleet's post-compromise toolset.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days