home.social

#httptroy — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #httptroy, aggregated by home.social.

  1. Gen Digital disclosure: Kimsuky deployed HttpTroy via a spear-phish ZIP (250908_A_HK이노션_SecuwaySSL VPN Manager U100S 100user_견적서.zip). Chain: dropper → MemLoad (sets scheduled task AhnlabUpdate) → HttpTroy (C2 load.auraria[.]org). Notable tech: custom API hashing, XOR/SIMD string obfuscation, dynamic API resolution, in-memory DLL execution. Capabilities include file transfer, screenshot capture, command execution, process termination, and trace cleanup.
    Suggested detection priorities:
    • Alert on new scheduled tasks with vendor-style names (AhnlabUpdate) and correlate to recent mail attachments.
    • Monitor processes performing in-memory DLL loads or unusual CreateProcessW patterns following SCR/ZIP executions.
    • Block or sandbox SCR files and scrutinize embedded decoy PDFs.

    Share your detection rules or SIGMA/YARA ideas in the comments — and follow @technadu for source-based threat intel.

    #ThreatIntel #MalwareAnalysis #HttpTroy #Kimsuky #MemLoad #EDR #Sigma #YARA #IncidentResponse #Infosec