#httptroy — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #httptroy, aggregated by home.social.
-
Gen Digital disclosure: Kimsuky deployed HttpTroy via a spear-phish ZIP (250908_A_HK이노션_SecuwaySSL VPN Manager U100S 100user_견적서.zip). Chain: dropper → MemLoad (sets scheduled task AhnlabUpdate) → HttpTroy (C2 load.auraria[.]org). Notable tech: custom API hashing, XOR/SIMD string obfuscation, dynamic API resolution, in-memory DLL execution. Capabilities include file transfer, screenshot capture, command execution, process termination, and trace cleanup.
Suggested detection priorities:
• Alert on new scheduled tasks with vendor-style names (AhnlabUpdate) and correlate to recent mail attachments.
• Monitor processes performing in-memory DLL loads or unusual CreateProcessW patterns following SCR/ZIP executions.
• Block or sandbox SCR files and scrutinize embedded decoy PDFs.Share your detection rules or SIGMA/YARA ideas in the comments — and follow @technadu for source-based threat intel.
#ThreatIntel #MalwareAnalysis #HttpTroy #Kimsuky #MemLoad #EDR #Sigma #YARA #IncidentResponse #Infosec