DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant
2025-10-30 • Gen Digital •
https://www.gendigital.com/blog/insights/research/dprk-kimsuky-lazarus-analysis
Gen Threat Labs details two DPRK-linked toolsets: Kimsuky’s newly named HttpTroy backdoor and a Lazarus chain using Comebacker to deploy a new BLINDINGCAN variant. The Kimsuky case targeted a victim in South Korea with a ZIP archive masquerading as a SecuwaySSL VPN invoice, executing a .scr dropper that showed a decoy PDF while registering a COM-based loader and a scheduled task named “AhnlabUpdate.” MemLoad_V3 decrypted and loaded HttpTroy in memory, giving operators file transfer, screenshot capture, command execution, process termination, trace removal, and HTTP POST C2 using XOR plus Base64 obfuscation. The Lazarus case targeted two victims in Canada, where Comebacker variants validated command-line parameters, decrypted payloads with HC256 and RC4, deployed a service DLL, and led toward BLINDINGCAN. The excerpt provides actionable indicators including SHA-256 hashes for the SCR, MemLoad_V3, and HttpTroy components, plus the C2 load.auraria.org/index.php.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 23.27.140.49 | 2025-10-30 | 2026-02-24 |
| HASH | 10c3b3ab2e9cb618fc938028c9295ad… | 2025-10-30 | 2025-10-30 |
| HASH | e19ce3bd1cbd980082d3c55a4ac1eb3… | 2025-10-30 | 2025-10-30 |
| HASH | c60587964a93b650f3442589b05e901… | 2025-10-30 | 2025-10-30 |
| HASH | 368769df7d319371073f33c29ad0097… | 2025-10-30 | 2025-10-30 |
| HASH | 20e0db1d2ad90bc46c7074c2cc116c2… | 2025-10-30 | 2025-10-30 |
| HASH | 509fb00b9d6eaa74f54a3d1f092a161… | 2025-10-30 | 2025-10-30 |
| HASH | b5eae8de6f5445e06b99eb8b0927f9a… | 2025-10-30 | 2025-10-30 |
| DOMAIN | load.auraria.org | 2025-10-30 | 2025-10-30 |
| DOMAIN | tronracing.com | 2025-10-30 | 2025-10-30 |
| IPv4 | 166.88.11.10 | 2025-10-30 | 2025-10-30 |