#TDrop2

Malware/Tool

2015-11-18 • TDrop2 Attacks Suggest Dark Seoul Attackers Return

TDrop2 is an updated member of the Tdrop malware family and has also been identified as a Dtrack variant, alongside Preft and HadesBot, despite implementation and execution differences. A 2015 cyberespionage campaign targeting Europe’s transportation sector embedded TDrop2 inside a legitimate video-software package hosted on a distributor’s website, creating a supply-chain delivery path to organizations using the distributor’s security-camera solution. Researchers connected the activity to the Dark Seoul and Operation Troy campaigns through strong similarities in functions, structure, tools, and tactics.

Tagged Reports

« Back