#PuTTY
Malware/Tool
2022-09-14 • It's Time to PuTTY! DPRK Job Opportunity Phishing via WhatsApp
PuTTY is a legitimate SSH and Telnet client that North Korean operators have distributed in trojanized form through fake recruitment approaches on LinkedIn, Telegram, WhatsApp, and freelancing platforms. Targeted archives paired a modified executable with connection details and a password. Entering the expected password triggered decryption and in-memory execution of an embedded payload. Observed infection chains installed SplitLoader components, established persistence through a scheduled task or Registry run key, and loaded additional malware after victims followed the attacker's connection instructions.
-
6
Tagged Reports
-
6
Unique Authors
-
887
Active Days