#Nikidoor

Malware/Tool

2024-03-19 • 국내 공공기관의 설치 파일을 위장한 악성코드 (Kimsuky 그룹)

Nikidoor is a backdoor attributed in the reports to the Kimsuky group. It has been distributed through spear-phishing activity and used alongside the Endoor backdoor. The malware can collect information from an infected system, receive commands, and perform attacker-directed actions. Observed infrastructure included an ngrok-free[.]app command-and-control address also shared with Endoor samples found in February and March 2024. The recurring string "Niki" in a reported PDB path is identified as a characteristic artifact.

Tagged Reports

« Back