SLICKSHOES is a Windows malware family attributed by U.S. government reporting to North Korean state-sponsored activity tracked as HIDDEN COBRA and commonly associated with the Lazarus Group. It has been characterized both as a loader or dropper and as a beacon-style implant with remote-access-trojan functionality. In observed use, an initial packed executable decodes and writes a second packed implant to disk, with separate stages responsible for dropping and later executing the payload.
The implanted component operates as a periodic beacon over TCP and uses a custom encoding scheme to protect command-and-control traffic. It transmits host profiling data including operating system and user context, then awaits tasking from the operator. Reported capabilities include system survey, file upload and download, process and command execution, and screen capture, indicating use for post-compromise host control and intelligence collection. The malware has also been described more broadly as a full beacon-style implant similar in operational role to Cobalt Strike.
SLICKSHOES targets Microsoft Windows systems and has been observed in packed form using Themida. Available reporting supports its role in payload delivery as well as follow-on remote access and host manipulation in North Korean intrusion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SLICKSHOES is typically utilized as a loader/Dropper. The malware writes itself to “C:WindowsWebtaskenc.exe”. Separate processes are responsible for the manipulation and execution of the dropped executable. SLICKSHOES is a full beacon-style implant (similar to Cobalt Strike).
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The initial beacon contains the string “ApolloZeus” as well as victim information, including OS version, user name, and IP address.
All traffic, including the beacon, is encoded with an indigenous encoding algorithm.
The implant beacons to a hardcoded IP (188.165.37.168) over the hardcoded TCP port 80 every 60 seconds.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus/Hidden Cobra loader-dropper and beacon-style implant that can write itself to disk, execute dropped payloads, communicate with a hardcoded C2, and perform RAT-like actions including file/process manipulation, reconnaissance, exfiltration, input capture, and command execution.
North Korean-linked Trojan malware delivered as a Themida-packed dropper that decodes and drops a beaconing implant to C:\Windows\Web\taskenc.exe. The implant beacons to a hardcoded C2 over TCP/80 every 60 seconds, sends victim information, and supports system survey, file upload/download, process execution, command execution, and screen capture.
A Lazarus-associated loader/dropper.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.