Elastic catches DPRK passing out KANDYKORN
ID: 7126dfa0-c885-53a0-b4bb-ba139d117c19
STIX ID: report--7126dfa0-c885-53a0-b4bb-ba139d117c19
Feed Name: Elastic Security Labs
Elastic Security Labs discloses REF7001, a DPRK-linked multi-stage intrusion that targeted blockchain engineers via a malicious Python “arbitrage bot” distributed over Discord; the chain comprises staging scripts (Watcher.py, testSpeed.py, FinderTools), an obfuscated loader SUGARLOADER (.sld/.log) that reflectively loads the final implant KANDYKORN, and a Discord-masquerading persistence loader (HLOADER). The report documents capabilities (remote command-and-control, file exfiltration, process and file manipulation, reflective in-memory execution), C2 infrastructure and IOCs, and provides detection guidance and hunting queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
