ATT&CKSoftwareTroll Stealer

Troll Stealer

S1196

Malware.View on attack.mitre.org

About this malware

Troll Stealer is an information stealer written in Go associated with Kimsuky operations. Troll Stealer has typically been delivered through a dropper disguised as a legitimate security program installation file. Troll Stealer features code similar to AppleSeed, also uniquely associated with Kimsuky operations.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1005
Data from Local System

Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note.

T1016
System Network Configuration Discovery

Troll Stealer collects the MAC address of victim devices.

T1027.002
Software Packing

Troll Stealer has been delivered as a VMProtect-packed binary.

T1036.005
Match Legitimate Resource Name or Location

Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file.

T1041
Exfiltration Over C2 Channel

Troll Stealer exfiltrates collected information to its command and control infrastructure.

T1059.001
PowerShell

Troll Stealer creates and executes a PowerShell script to delete itself.

T1059.003
Windows Command Shell

Troll Stealer can create and execute Windows batch scripts.

T1070.004
File Deletion

Troll Stealer creates and can execute a BAT script that will delete the malware.

T1071.001
Web Protocols

Troll Stealer uses HTTP to communicate to command and control infrastructure.

T1074.001
Local Data Staging

Troll Stealer encrypts gathered information on victim devices prior to exfiltrating it through command and control infrastructure.

T1082
System Information Discovery

Troll Stealer can collect local system information.

T1083
File and Directory Discovery

Troll Stealer can enumerate and collect items from local drives and folders.

T1113
Screen Capture

Troll Stealer can capture screenshots from victim machines.

T1132.001
Standard Encoding

Troll Stealer performs XOR encryption and Base64 encoding of data prior to sending to command and control infrastructure.

T1213
Data from Information Repositories

Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems.

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. S2W Troll Stealer 2024 Open source
    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.
  2. Symantec Troll Stealer 2024 Open source
    Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.