#Xctdoor
Malware/Tool
2024-06-24 • 국내 기업 대상 공격에 사용 중인 Xctdoor 악성코드 (Andariel)
Xctdoor is a Windows backdoor used in campaigns targeting South Korean organizations, including defense and manufacturing companies, and linked in reporting to North Korea-associated activity involving Andariel and the Larva-26005 cluster. Delivered in C++ and Go variants, it is commonly loaded by XcLoader through process injection and establishes persistence from AppX-style package paths. Xctdoor sends host information to its command-and-control server, executes operator commands, and supports screenshot capture, keylogging, clipboard logging, and drive enumeration. Observed delivery methods include compromised web and ERP update servers, trojanized installers, and malicious LNK files.
-
7
Tagged Reports
-
3
Unique Authors
-
774
Active Days