HTTPTroy

S9007

Malware.View on attack.mitre.org

About this malware

HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. HTTPTroy was first reported in October 2025. HTTPTroy has been observed in operations attributed to DPRK-affiliated threat actors, including Kimsuky. HTTPTroy has been delivered to victims through a separate loader leveraged by Kimsuky.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1027
Obfuscated Files or Information

HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection.

T1027.007
Dynamic API Resolution

HTTPTroy has utilized dynamic API resolution by reconstructing API calls during runtime using combinations of arithmetic and logical operations to complicate static analysis.

T1041
Exfiltration Over C2 Channel

HTTPTroy has exfiltrated encrypted data over the C2 channel using the `up <FILENAME>` command.

T1059.003
Windows Command Shell

HTTPTroy has the ability to generate a reverse shell using the command `conn <IP_ADDRESS> <PORT>`.

T1070.004
File Deletion

HTTPTroy can terminate its running process and then remove traces of itself through the `die <COMMAND>` command.

T1071.001
Web Protocols

HTTPTroy has used HTTP POST requests to communicate with C2.

T1105
Ingress Tool Transfer

HTTPTroy has the ability to download files from C2 using the `down <FILENAME>` command.

T1106
Native API

HTTPTroy has leveraged Windows Native API calls, including `GetProcAddress` to execute functions in memory.

T1113
Screen Capture

HTTPTroy has obtained screen captures leveraging the `screen` command which captures, encrypts and uploads the stolen image to the adversary controlled C2 server.

T1132.002
Non-Standard Encoding

HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding.

T1140
Deobfuscate/Decode Files or Information

HTTPTroy has decoded strings encoded with Base64 and XOR prior to execution.

T1548.002
Bypass User Account Control

HTTPTroy has leveraged the ability to execute commands with system privileges using the `srun <EXECUTABLE> <ARGS>` command.

T1573.001
Symmetric Cryptography

HTTPTroy has obfuscated request communications utilizing XOR encryption.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Gen Digital Kimsuky HTTPTroy October 2025 Open source
    Alexndru-Cristian Bardas. (2025, October 30). DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant. Retrieved April 8, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.