#VIVACIOUSGIFT
Malware/Tool
2020-08-26 • MAR-10301706-2.v1 - North Korean Remote Access Tool: VIVACIOUSGIFT
VIVACIOUSGIFT is a Windows network-proxy tool used by the North Korean government and associated in U.S. reporting with HIDDEN COBRA. It accepts encrypted command-line configuration that defines source and destination addresses, ports, an optional upstream proxy, and a proxy password. The malware can also receive command-and-control instructions that set a destination and activate proxying. It opens connections to the configured endpoints and relays encrypted traffic between them, using libcurl for HTTP proxy tunneling when required. CISA detection material identifies the analyzed family as TWOPENCE and provides YARA and Snort signatures for its command strings and proxy handshake.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days