#OdicLoader

Malware/Tool

2024-09-09 • Threat Assessment: North Korean Threat Groups

OdicLoader is a Linux ELF downloader associated with Selective Pisces and first observed in 2023. It masquerades as a PDF by replacing the normal period before the pdf extension with the visually similar Unicode U+2024 character, causing graphical Linux file managers to execute the ELF when a victim double-clicks it. OdicLoader opens a decoy PDF through xdg-open, then downloads and executes a next-stage payload; it has been linked to Operation DreamJob.

Tagged Reports

« Back