#PuTTY

Malware/Tool

2022-09-14 • It's Time to PuTTY! DPRK Job Opportunity Phishing via WhatsApp

PuTTY is a legitimate SSH and Telnet client that North Korean operators have distributed in trojanized form through fake recruitment approaches on LinkedIn, Telegram, WhatsApp, and freelancing platforms. Targeted archives paired a modified executable with connection details and a password. Entering the expected password triggered decryption and in-memory execution of an embedded payload. Observed infection chains installed SplitLoader components, established persistence through a scheduled task or Registry run key, and loaded additional malware after victims followed the attacker's connection instructions.

Tagged Reports

« Back