logo

North Korean Hackers Deploy New Golang Malware 'Durian' Against Crypto Firms

ID: 2f5d0aff-4aa1-50db-b3d7-550db3f26997

STIX ID: report--2f5d0aff-4aa1-50db-b3d7-550db3f26997

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-05-10

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Kimsuky (a North Korean APT) has been observed deploying a newly documented Golang backdoor called Durian in highly targeted attacks against two South Korean cryptocurrency firms (Aug & Nov 2023); Durian provides backdoor capabilities, additional payload delivery, and browser credential exfiltration, and was distributed via a legitimate South Korean application as an infection vector, with follow-on deployment of tools such as AppleSeed, LazyLoad, ngrok, and Chrome Remote Desktop.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.