North Korean Trojan: HARDRAIN
2018-02-13 • USCISA •
https://www.us-cert.gov/sites/default/files/publications/MAR-10135536-F.pdf
Attachments
DHS and FBI describe HARDRAIN as HIDDEN COBRA malware used by North Korean government actors with proxy servers to maintain access and support further exploitation. The MAR analyzes three files: two 32-bit Windows executables that act as proxy servers using fake TLS behavior and one Android ELF RAT. One Windows DLL opens the host firewall for incoming connections, disguises proxy traffic as TLS by embedding legitimate public SSL certificate strings, and uses an unidentified cipher for operator communications.
Related Actors
Related Reports
Shares tag: HiddenCobra • Same author: USCISA • Published within a week
Shares tag: HiddenCobra • Same author: USCISA
Shares tag: HiddenCobra • Published within a month
Shares tag: HiddenCobra • Same author: USCISA
Shares tag: HiddenCobra • Same author: USCISA
Shares tag: HiddenCobra • Same author: USCISA