#OdicLoader
Malware/Tool
2024-09-09 • Threat Assessment: North Korean Threat Groups
OdicLoader is a Linux ELF downloader associated with Selective Pisces and first observed in 2023. It masquerades as a PDF by replacing the normal period before the pdf extension with the visually similar Unicode U+2024 character, causing graphical Linux file managers to execute the ELF when a victim double-clicks it. OdicLoader opens a decoy PDF through xdg-open, then downloads and executes a next-stage payload; it has been linked to Operation DreamJob.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days