South Korean ERP Vendor's Server Hacked to Spread Xctdoor Malware
ID: 3df26179-dd51-543d-b752-3e9f06cd21b8
STIX ID: report--3df26179-dd51-543d-b752-3e9f06cd21b8
Feed Name: The Hacker News
ASEC discovered that a South Korean ERP vendor's update server was compromised to deliver a Go-based backdoor (Xctdoor) which, when injected by XcLoader into legitimate processes via regsvr32-executed DLLs, can capture keystrokes, screenshots, and clipboard data and execute remote commands; communication with C2 uses HTTP with MT19937 and Base64 obfuscation. The report also links similar tactics to North Korea-associated clusters (Andariel/Lazarus, Kimusky) and describes additional phishing-driven campaigns (HappyDoor, Konni) targeting South Korea.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
