Analysis on the Case of TIDRONE Threat Actor’s Attacks on Korean Companies
ID: 43e90d4d-c459-5987-b2b9-65bc40108ef0
STIX ID: report--43e90d4d-c459-5987-b2b9-65bc40108ef0
Feed Name: ASEC
Threat Score
AhnLab ASEC reports that the TIDRONE threat actor has been exploiting small/limited-distribution Korean ERP software (and previously Taiwanese targets) to distribute a RAT called CLNTEND via DLL side‑loading and droppers; the report provides technical analysis of loaders, decryption techniques (including FlsCallback usage), execution paths, sample detections, MD5 hashes and FQDNs, and recommends updating endpoint protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
