Alexndru-Cristian Bardas. (2025, October 30). DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant. Retrieved April 8, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupKimsuky | Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis. |
| T1027 Obfuscated Files or Information |
MalwareHTTPTroy | HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection. |
| T1027.007 Dynamic API Resolution |
MalwareHTTPTroy | HTTPTroy has utilized dynamic API resolution by reconstructing API calls during runtime using combinations of arithmetic and logical operations to complicate static analysis. |
| T1027.007 Dynamic API Resolution |
GroupKimsuky | Kimsuky has leveraged dynamic API resolution using custom hashing techniques. |
| T1027.013 Encrypted/Encoded File |
GroupKimsuky | Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads. |
| T1027.015 Compression |
GroupKimsuky | Kimsuky has delivered malicious payloads within Zip archives. |
| T1041 Exfiltration Over C2 Channel |
MalwareHTTPTroy | HTTPTroy has exfiltrated encrypted data over the C2 channel using the `up <FILENAME>` command. |
| T1053.005 Scheduled Task |
GroupKimsuky | Kimsuky has downloaded additional malware with scheduled tasks. Kimsuky has established persistence by creating a scheduled task named “ChromeUpdateTaskMachine” through the PowerShell cmdlet `Register-ScheduleTask` which was set to execute another PowerShell script once, then five minutes after its creation and periodically repeat every 30 minutes. Kimsuky has also set scheduled tasks that run periodically using the PT1M repetition pattern leveraging naming conventions of Anti-Virus software to include "AhnlabUpdate". |
| T1059.003 Windows Command Shell |
MalwareHTTPTroy | HTTPTroy has the ability to generate a reverse shell using the command `conn <IP_ADDRESS> <PORT>`. |
| T1059.003 Windows Command Shell |
GroupKimsuky | Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT. |
| T1070.004 File Deletion |
MalwareHTTPTroy | HTTPTroy can terminate its running process and then remove traces of itself through the `die <COMMAND>` command. |
| T1071.001 Web Protocols |
MalwareHTTPTroy | HTTPTroy has used HTTP POST requests to communicate with C2. |
| T1105 Ingress Tool Transfer |
MalwareHTTPTroy | HTTPTroy has the ability to download files from C2 using the `down <FILENAME>` command. |
| T1106 Native API |
GroupKimsuky | Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts. |
| T1106 Native API |
MalwareHTTPTroy | HTTPTroy has leveraged Windows Native API calls, including `GetProcAddress` to execute functions in memory. |
| T1113 Screen Capture |
MalwareHTTPTroy | HTTPTroy has obtained screen captures leveraging the `screen` command which captures, encrypts and uploads the stolen image to the adversary controlled C2 server. |
| T1113 Screen Capture |
GroupKimsuky | Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware. |
| T1132.002 Non-Standard Encoding |
MalwareHTTPTroy | HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding. |
| T1132.002 Non-Standard Encoding |
GroupKimsuky | Kimsuky has obfuscated HTTP Post request communications utilizing XOR with a designated key, followed by Base64 encoding. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHTTPTroy | HTTPTroy has decoded strings encoded with Base64 and XOR prior to execution. |
| T1204.002 Malicious File |
GroupKimsuky | Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background. |
| T1218.010 Regsvr32 |
GroupKimsuky | Kimsuky has executed malware with |
| T1480.002 Mutual Exclusion |
GroupKimsuky | Kimsuky has utilized a mutex to detect whether its malware is actively running on the victim host. Kimsuky has leveraged PowerShell to store the Process ID (PID) of the currently running malicious PowerShell script into a file named pid.txt which is saved locally on the victim host in the %TEMP% Directory and is queried prior to execution of subsequent PowerShell script to prevent duplication. |
| T1548.002 Bypass User Account Control |
MalwareHTTPTroy | HTTPTroy has leveraged the ability to execute commands with system privileges using the `srun <EXECUTABLE> <ARGS>` command. |
| T1559.001 Component Object Model |
GroupKimsuky | Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment. |
| T1573.001 Symmetric Cryptography |
MalwareHTTPTroy | HTTPTroy has obfuscated request communications utilizing XOR encryption. |
| T1678 Delay Execution |
GroupKimsuky | Kimsuky has utilized the Sleep function to ensure execution of scripts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.