#Nikidoor
Malware/Tool
2024-03-19 • 국내 공공기관의 설치 파일을 위장한 악성코드 (Kimsuky 그룹)
Nikidoor is a backdoor attributed in the reports to the Kimsuky group. It has been distributed through spear-phishing activity and used alongside the Endoor backdoor. The malware can collect information from an infected system, receive commands, and perform attacker-directed actions. Observed infrastructure included an ngrok-free[.]app command-and-control address also shared with Endoor samples found in February and March 2024. The recurring string "Niki" in a reported PDB path is identified as a characteristic artifact.
-
2
Tagged Reports
-
1
Unique Authors
-
8
Active Days