Hisoka is a custom backdoor associated with the xHunt espionage cluster, which has targeted organizations in Kuwait, particularly in the transportation, shipping, and government sectors. It was observed in 2019 as part of a broader toolset that also included Sakabota, Killua, Gon, EYE, Netero, TriFive, and Snugy. Analysis indicates Hisoka shares substantial development lineage with Sakabota and is likely part of the same evolving malware ecosystem.
Hisoka functions as a covert remote-access implant used after compromise to maintain access and execute operator tasking. Multiple variants were observed. Earlier variants used HTTP and DNS tunneling for command and control, while version 0.9 added a more unusual email-based channel that abused Exchange Web Services. In that mode, the malware authenticated with stolen credentials to a legitimate Exchange account and exchanged commands and results through saved draft messages rather than normal sent mail, using mailbox folders as a stealthy command channel. This tradecraft aligns with xHunt’s emphasis on blending malicious traffic into legitimate enterprise services.
Operational reporting places Hisoka in intrusions against Kuwaiti transportation and shipping organizations, where it served as an initial foothold for follow-on activity. After access through Hisoka, operators deployed additional post-exploitation tooling for reconnaissance, remote command execution, network discovery, and operational cleanup. The malware family is therefore best understood as a persistence and command-and-control backdoor within a bespoke espionage framework rather than a commodity implant.
Hisoka is linked to long-term intelligence collection operations focused on sensitive organizations in Kuwait. Its use of multiple command channels, including DNS tunneling and Exchange-based draft messaging, demonstrates an emphasis on resilience, stealth, and defense evasion. The malware is associated with xHunt activity, although broader attribution overlaps with other regional intrusion activity have remained unconfirmed at the operator level.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This same general technique was used by the email-based C2 in the Hisoka tool discussed in the initial publication about the xHunt campaign.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Hisoka is a backdoor malware that uses both HTTP and DNS tunneling for C2 communication. | These tools not only use HTTP for their command and control (C2) channels, but certain variants of these tools use DNS tunneling or emails to communicate with their C2 as well.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom backdoor used by xHunt APT for cyber-espionage, enabling persistent access and intelligence harvesting from compromised systems.
Custom backdoor leveraging Exchange Web Services (EWS) for stealthy C2 via mailbox draft manipulation (e.g., Drafts/Deleted Items).
Malware associated with xHunt referenced here through overlap in command-and-control domain naming patterns. The content does not provide additional functional detail in this article.
A tool previously used in the xHunt campaign that employed an email-based command-and-control technique using email drafts; Netero is referenced as a variant name associated with Hisoka.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.