AhnLab ASEC. (2024, February 16). TrollAgent That Infects Systems Upon Security Program Installation Process (Kimsuky Group). Retrieved January 17, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareTroll Stealer | Troll Stealer has been delivered as a VMProtect-packed binary. |
| T1218.011 Rundll32 |
MalwareTroll Stealer | Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer. |
| T1553.002 Code Signing |
MalwareTroll Stealer | Troll Stealer, along with its associated dropper, utilizes legitimate, stolen code signing certificates. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.