A previously unreported backdoor dubbed HttpTroy was disseminated by the North Korea-affiliated threat actor Kimsuky as part of a probable spear-phishing operation that was directed at a single South Korean victim.
The activity’s disclosure company, Gen Digital, did not specify when the incident happened, but it did mention that the phishing email included a ZIP file (“250908_A_HK이노慘SecuwaySSL VPN Manager U100S 100user`�{栁愜.zip”) that disseminated malware that could transfer files, take screenshots, and run arbitrary commands by posing as a VPN invoice.
Three steps comprise the chain: a tiny dropper, a loader named MemLoad, and the last backdoor, termed ‘HttpTroy,’ according to security researcher Alexandru-Cristian Bardaș.
The same-named SCR file is included in the ZIP archive; it opened to initiate the execution chain, which began with a Golang binary read more about New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
