#TightVNC

Malware/Tool

2018-10-03 • APT38 Un-usual Suspects

TightVNC is legitimate open-source remote-control software that North Korean operators customized or weaponized in Windows campaigns. Lazarus distributed a modified viewer disguised as Amazon Workspaces inside a Skill Assessment ISO; it collected user, computer, motherboard, and workgroup data, Base64-encoded the results, and launched an encrypted in-memory backdoor after the victim selected provided server details. Another Lazarus package presented a modified build as ComcastVNC and paired it with DLL side-loading and BlindingCan. Kimsuky also deployed a customized tvnserver through AppleSeed so infected hosts initiated reverse-VNC connections for graphical control.

Tagged Reports

« Back