logo

North Korean Hackers Using New ‘HappyDoor’ Malware Used In Email Attacks

ID: 3f7bd9b6-0cd7-5fa5-8897-69c24d9c1430

STIX ID: report--3f7bd9b6-0cd7-5fa5-8897-69c24d9c1430

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2024-06-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

HappyDoor is a Kimsuky-linked backdoor/infostealer active from 2021 through 2024 and distributed via spear-phishing attachments (obfuscated JScript/executable droppers); it executes in staged arguments via regsvr32, supports screenshot capture, keylogging, file exfiltration, microphone recording, RSA-encrypted data exfiltration over HTTP to multiple C2 servers, and the report includes sample MD5 hashes and C2 URLs and recommends caution with email attachments and keeping software updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.