#Niki

Malware/Tool

2024-06-19 • New North-Korean based backdoor packs a punch

Niki is a multi-stage backdoor campaign and associated malware set targeting aerospace and defense companies with a fake Safety Manager job description. The lure used a file named with a .zip extension that was actually a RAR archive containing an obfuscated JSE dropper. The script decoded a decoy PDF and a doubly Base64-encoded payload into ProgramData, opened the decoy, used certutil to decode the malware, and launched the resulting DLL with regsvr32. Researchers named Niki after strings referring to possible developers and linked the activity broadly to North Korean tradecraft without assigning it to a definitive operator.

Tagged Reports

« Back