216.73.216.226

Kimsuky Group’s New Backdoor (HappyDoor)

· Published 08/07/2024 18:34 · Modified 08/07/2024 19:26

Export JSON

Essential information

Published
08/07/2024 18:34
Modified
08/07/2024 19:26
Tags
2024-07-08 alphaseed happydoor infostealing keylogger pebbledash powershell regsvr32
Related entities
7 observables, 1 intrusion sets (apt), 12 techniques (mitre), 1 malware

Description

This report provides a detailed analysis of the malware, a new backdoor utilized by the Kimsuky threat group known for targeting organizations with spear-phishing attacks. The malware employs sophisticated techniques like self-duplication, hidden execution paths, and encrypted communication to maintain persistence and evade detection. is equipped with various malicious capabilities, including information theft through keylogging, file exfiltration, and voice recording, as well as backdoor functionalities allowing remote control and code execution. The analysis covers the malware's distribution methods, execution flow, communication protocols, registry configurations, and a comprehensive list of its features.

External references