North Korean Hackers Deploy New Golang Malware 'Durian' Against Crypto Firms
ID: 2f5d0aff-4aa1-50db-b3d7-550db3f26997
STIX ID: report--2f5d0aff-4aa1-50db-b3d7-550db3f26997
Feed Name: The Hacker News
Threat Score
Kimsuky (a North Korean APT) has been observed deploying a newly documented Golang backdoor called Durian in highly targeted attacks against two South Korean cryptocurrency firms (Aug & Nov 2023); Durian provides backdoor capabilities, additional payload delivery, and browser credential exfiltration, and was distributed via a legitimate South Korean application as an infection vector, with follow-on deployment of tools such as AppleSeed, LazyLoad, ngrok, and Chrome Remote Desktop.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
