logo

South Korean ERP Vendor's Server Hacked to Spread Xctdoor Malware

ID: 3df26179-dd51-543d-b752-3e9f06cd21b8

STIX ID: report--3df26179-dd51-543d-b752-3e9f06cd21b8

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-07-03

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

ASEC discovered that a South Korean ERP vendor's update server was compromised to deliver a Go-based backdoor (Xctdoor) which, when injected by XcLoader into legitimate processes via regsvr32-executed DLLs, can capture keystrokes, screenshots, and clipboard data and execute remote commands; communication with C2 uses HTTP with MT19937 and Base64 obfuscation. The report also links similar tactics to North Korea-associated clusters (Andariel/Lazarus, Kimusky) and describes additional phishing-driven campaigns (HappyDoor, Konni) targeting South Korea.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.