ATT&CKReferencesUS-CERT HOTCROISSANT February 2020

US-CERT HOTCROISSANT February 2020

US-CERT. (2020, February 20). MAR-10271944-1.v1 – North Korean Trojan: HOTCROISSANT. Retrieved May 1, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareHotCroissant

HotCroissant has the ability to identify the IP address of the compromised machine.

T1082
System Information Discovery
MalwareHotCroissant

HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host.

T1106
Native API
MalwareHotCroissant

HotCroissant can perform dynamic DLL importing and API lookups using LoadLibrary and GetProcAddress on obfuscated strings.

T1573.001
Symmetric Cryptography
MalwareHotCroissant

HotCroissant has compressed network communications and encrypted them with a custom stream cipher.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.