#TrollAgent

Malware/Tool

2024-02-16 • 보안 프로그램 설치 과정에서 감염되는 TrollAgent (Kimsuky 그룹)

TrollAgent is a Go-based information-stealing DLL used in Kimsuky activity against Korean construction-related and public-sector targets. It was packed with VMProtect, signed with a stolen valid D2Innovation certificate, and bundled with installers masquerading as required security software, so a legitimate program appeared to install while the malicious DLL ran through rundll32.exe from %APPDATA%. TrollAgent collects system data, screenshots, selected files, browser credentials, cookies, bookmarks, history and extensions, as well as GPKI certificates, SSH keys, Sticky Notes, and FileZilla information. One analysis says collected data is XOR-encrypted, Base64-encoded, and sent to a C2 server after an initialization exchange.

Tagged Reports

« Back