ATT&CKReferencesASEC Troll Stealer 2024

ASEC Troll Stealer 2024

AhnLab ASEC. (2024, February 16). TrollAgent That Infects Systems Upon Security Program Installation Process (Kimsuky Group). Retrieved January 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareTroll Stealer

Troll Stealer has been delivered as a VMProtect-packed binary.

T1218.011
Rundll32
MalwareTroll Stealer

Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer.

T1553.002
Code Signing
MalwareTroll Stealer

Troll Stealer, along with its associated dropper, utilizes legitimate, stolen code signing certificates.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.