Kimusk’s HappyDoor: regsvr32 Exploit Evades Detection
ID: 24e02195-829c-5720-b068-8710ee7e25e8
STIX ID: report--24e02195-829c-5720-b068-8710ee7e25e8
Feed Name: Cyber Press
HappyDoor is an actively developed backdoor and information stealer attributed to the Kimsuky group that is distributed via spear-phishing and JScript droppers; it persists using registry-stored configuration, communicates with a custom HTTP-based C2 protocol, and can capture screenshots, keystrokes, audio, and files while supporting remote commands and encrypted exfiltration. Researchers observed continuous updates and evolving execution arguments and obfuscation techniques between 2021 and early 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
