#TrollStealer

Malware/Tool

2024-02-07 • Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer

TrollStealer is a Go-based Windows information stealer associated with Kimsuky and delivered through trojanized Korean security-software installers signed with a valid certificate. Its dropper runs a legitimate installer, loads the malicious DLL with rundll32, and later deletes artifacts. TrollStealer inventories processes, software, directories, and antivirus products; captures screenshots; and steals SSH, FileZilla, Sticky Notes, browser, and Government Public Key Infrastructure data. It compresses and encrypts collected material before sending it to HTTP command-and-control servers. Targeting of the GPKI directory indicates a focus on South Korean administrative and public-sector systems.

Tagged Reports

« Back