#Tropidoor
Malware/Tool
2025-04-02 • 채용 메일을 위장한 피싱 공격 정황 사례 분석 (BeaverTail, Tropidoor)
Tropidoor is a Windows backdoor delivered in DPRK-linked DeceptiveDevelopment campaigns through trojanized Bitbucket projects. A 64-bit downloader, observed as car.dll or img_layer_generate.dll, retrieved Tropidoor directly into memory while parallel components delivered BeaverTail and InvisibleFerret. Researchers found substantial code overlap with PostNapTea, a Lazarus RAT used against South Korean targets in 2022. The families share API hashing and Base64 plus AES-128 network encryption, although Tropidoor is implemented as a C DLL and used in social-engineering operations.
-
3
Tagged Reports
-
2
Unique Authors
-
177
Active Days