DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant

2025-10-30 Gen Digital

https://www.gendigital.com/blog/insights/research/dprk-kimsuky-lazarus-analysis

Thumbnail for DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant

Gen Threat Labs details two DPRK-linked toolsets: Kimsuky’s newly named HttpTroy backdoor and a Lazarus chain using Comebacker to deploy a new BLINDINGCAN variant. The Kimsuky case targeted a victim in South Korea with a ZIP archive masquerading as a SecuwaySSL VPN invoice, executing a .scr dropper that showed a decoy PDF while registering a COM-based loader and a scheduled task named “AhnlabUpdate.” MemLoad_V3 decrypted and loaded HttpTroy in memory, giving operators file transfer, screenshot capture, command execution, process termination, trace removal, and HTTP POST C2 using XOR plus Base64 obfuscation. The Lazarus case targeted two victims in Canada, where Comebacker variants validated command-line parameters, decrypted payloads with HC256 and RC4, deployed a service DLL, and led toward BLINDINGCAN. The excerpt provides actionable indicators including SHA-256 hashes for the SCR, MemLoad_V3, and HttpTroy components, plus the C2 load.auraria.org/index.php.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 23.27.140.49 2025-10-30 2026-02-24
HASH 10c3b3ab2e9cb618fc938028c9295ad… 2025-10-30 2025-10-30
HASH e19ce3bd1cbd980082d3c55a4ac1eb3… 2025-10-30 2025-10-30
HASH c60587964a93b650f3442589b05e901… 2025-10-30 2025-10-30
HASH 368769df7d319371073f33c29ad0097… 2025-10-30 2025-10-30
HASH 20e0db1d2ad90bc46c7074c2cc116c2… 2025-10-30 2025-10-30
HASH 509fb00b9d6eaa74f54a3d1f092a161… 2025-10-30 2025-10-30
HASH b5eae8de6f5445e06b99eb8b0927f9a… 2025-10-30 2025-10-30
DOMAIN load.auraria.org 2025-10-30 2025-10-30
DOMAIN tronracing.com 2025-10-30 2025-10-30
IPv4 166.88.11.10 2025-10-30 2025-10-30

Related Actors

Related Reports

« Back