ATT&CKReferencesGen Digital Kimsuky HTTPTroy October 2025

Gen Digital Kimsuky HTTPTroy October 2025

Alexndru-Cristian Bardas. (2025, October 30). DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant. Retrieved April 8, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupKimsuky

Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis.

T1027
Obfuscated Files or Information
MalwareHTTPTroy

HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection.

T1027.007
Dynamic API Resolution
MalwareHTTPTroy

HTTPTroy has utilized dynamic API resolution by reconstructing API calls during runtime using combinations of arithmetic and logical operations to complicate static analysis.

T1027.007
Dynamic API Resolution
GroupKimsuky

Kimsuky has leveraged dynamic API resolution using custom hashing techniques.

T1027.013
Encrypted/Encoded File
GroupKimsuky

Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads.

T1027.015
Compression
GroupKimsuky

Kimsuky has delivered malicious payloads within Zip archives.

T1041
Exfiltration Over C2 Channel
MalwareHTTPTroy

HTTPTroy has exfiltrated encrypted data over the C2 channel using the `up <FILENAME>` command.

T1053.005
Scheduled Task
GroupKimsuky

Kimsuky has downloaded additional malware with scheduled tasks. Kimsuky has established persistence by creating a scheduled task named “ChromeUpdateTaskMachine” through the PowerShell cmdlet `Register-ScheduleTask` which was set to execute another PowerShell script once, then five minutes after its creation and periodically repeat every 30 minutes. Kimsuky has also set scheduled tasks that run periodically using the PT1M repetition pattern leveraging naming conventions of Anti-Virus software to include "AhnlabUpdate".

T1059.003
Windows Command Shell
MalwareHTTPTroy

HTTPTroy has the ability to generate a reverse shell using the command `conn <IP_ADDRESS> <PORT>`.

T1059.003
Windows Command Shell
GroupKimsuky

Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT.

T1070.004
File Deletion
MalwareHTTPTroy

HTTPTroy can terminate its running process and then remove traces of itself through the `die <COMMAND>` command.

T1071.001
Web Protocols
MalwareHTTPTroy

HTTPTroy has used HTTP POST requests to communicate with C2.

T1105
Ingress Tool Transfer
MalwareHTTPTroy

HTTPTroy has the ability to download files from C2 using the `down <FILENAME>` command.

T1106
Native API
GroupKimsuky

Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts.

T1106
Native API
MalwareHTTPTroy

HTTPTroy has leveraged Windows Native API calls, including `GetProcAddress` to execute functions in memory.

T1113
Screen Capture
MalwareHTTPTroy

HTTPTroy has obtained screen captures leveraging the `screen` command which captures, encrypts and uploads the stolen image to the adversary controlled C2 server.

T1113
Screen Capture
GroupKimsuky

Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware.

T1132.002
Non-Standard Encoding
MalwareHTTPTroy

HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding.

T1132.002
Non-Standard Encoding
GroupKimsuky

Kimsuky has obfuscated HTTP Post request communications utilizing XOR with a designated key, followed by Base64 encoding.

T1140
Deobfuscate/Decode Files or Information
MalwareHTTPTroy

HTTPTroy has decoded strings encoded with Base64 and XOR prior to execution.

T1204.002
Malicious File
GroupKimsuky

Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background.

T1218.010
Regsvr32
GroupKimsuky

Kimsuky has executed malware with regsvr32s.

T1480.002
Mutual Exclusion
GroupKimsuky

Kimsuky has utilized a mutex to detect whether its malware is actively running on the victim host. Kimsuky has leveraged PowerShell to store the Process ID (PID) of the currently running malicious PowerShell script into a file named pid.txt which is saved locally on the victim host in the %TEMP% Directory and is queried prior to execution of subsequent PowerShell script to prevent duplication.

T1548.002
Bypass User Account Control
MalwareHTTPTroy

HTTPTroy has leveraged the ability to execute commands with system privileges using the `srun <EXECUTABLE> <ARGS>` command.

T1559.001
Component Object Model
GroupKimsuky

Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment.

T1573.001
Symmetric Cryptography
MalwareHTTPTroy

HTTPTroy has obfuscated request communications utilizing XOR encryption.

T1678
Delay Execution
GroupKimsuky

Kimsuky has utilized the Sleep function to ensure execution of scripts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.