HttpTroy is a Kimsuky-associated backdoor used in espionage-oriented intrusions, particularly against South Korean targets. It has been observed as the final payload in a multistage infection chain in which an initial dropper deploys the MemLoad loader, which then decrypts and memory-loads the backdoor. Reported delivery has included spearphishing with ZIP lures themed as business documents such as VPN quotations or invoices, and related campaigns have also targeted South Korean groupware vendors and downstream customer environments.
HttpTroy is designed to provide long-term remote access and broad control over compromised Windows systems. Documented capabilities include command execution, file upload and download, screenshot capture, reverse shell functionality, in-memory loading and execution of additional payloads, process termination, and trace removal. It has also been reported to support execution of commands with system privileges through a dedicated command mechanism. Communications with command-and-control infrastructure use HTTP POST, with observed traffic obfuscated through XOR and Base64-style encoding. Samples have been described as heavily obfuscated and as using runtime API reconstruction and string-hiding techniques to complicate analysis and detection.
Persistence has been established through scheduled tasks in observed campaigns. HttpTroy has been linked to Kimsuky and to the Kimsuky-affiliated cluster Larva-25004. It also appears related in development lineage or tradecraft to other Kimsuky malware families including Gomir and BirdTroy, which share command logic or persistence patterns. The malware fits Kimsuky’s broader pattern of targeted credential theft, espionage, and sustained access operations against government, military, corporate, and supply-chain-adjacent organizations in South Korea.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The first campaign, attributed to Kimsuky, leveraged a VPN-invoice themed ZIP lure to drop a loader (“MemLoad”) and a new backdoor dubbed “HttpTroy”.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
"국내 그룹웨어 대상 북한 APT 공격 분석" published by ENKI. #Kimsuky, #Phishing, #Slides, #Gomir, #HttpTroy
HTTPSpy is a full-featured remote access trojan that supports a wide range of capabilities to run shell commands, upload/download files, execute processes, capture screenshots, inject DLL paths into specified PID processes, and erase itself from the endpoint.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
Supporte 17 codes de commande : shell, transfert de fichiers, proxy, hibernation, etc.
These attachments often consist of compressed files containing droppers in formats such as .JSE, .EXE, .PIF, or .SCR. The filenames are consistent with the message content and are meant to convince the recipient to open the attachment.
HTTPSpy is a full-featured remote access trojan that supports a wide range of capabilities to run shell commands, upload/download files, execute processes, capture screenshots, inject DLL paths into specified PID processes, and erase itself from the endpoint.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
HttpMalice, the latest backdoor variant of PebbleDash, emerged no later than December 2025. It comes with capabilities to gather information about the compromised system, set up persistence, perform reconnaissance using native Windows commands, capture screenshots, load downloaded payloads into memory, run commands, and exfiltrate the execution output.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
"국내 그룹웨어 대상 북한 APT 공격 분석" published by ENKI. #Kimsuky, #Phishing, #Slides, #Gomir, #HttpTroy
RAT used in the same Kimsuky campaign via spear-phishing against a vendor employee; it shares command codes and persistence logic with BirdTroy and Gomir.
Mentioned as a related malware/tool via hashtag in the post, but without further detail in the provided content.
Referenced as a malware family whose command structure and features overlap with BirdTroy; also listed with an MD5 in the report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.