North Korean Hackers Using New ‘HappyDoor’ Malware Used In Email Attacks
ID: 3f7bd9b6-0cd7-5fa5-8897-69c24d9c1430
STIX ID: report--3f7bd9b6-0cd7-5fa5-8897-69c24d9c1430
Feed Name: cybersecurityNews.com
HappyDoor is a Kimsuky-linked backdoor/infostealer active from 2021 through 2024 and distributed via spear-phishing attachments (obfuscated JScript/executable droppers); it executes in staged arguments via regsvr32, supports screenshot capture, keylogging, file exfiltration, microphone recording, RSA-encrypted data exfiltration over HTTP to multiple C2 servers, and the report includes sample MD5 hashes and C2 URLs and recommends caution with email attachments and keeping software updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
