Malware.View on attack.mitre.org
HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. HTTPTroy was first reported in October 2025. HTTPTroy has been observed in operations attributed to DPRK-affiliated threat actors, including Kimsuky. HTTPTroy has been delivered to victims through a separate loader leveraged by Kimsuky.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
HTTPTroy has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions to hinder analysis and detection. |
| T1027.007 Dynamic API Resolution |
HTTPTroy has utilized dynamic API resolution by reconstructing API calls during runtime using combinations of arithmetic and logical operations to complicate static analysis. |
| T1041 Exfiltration Over C2 Channel |
HTTPTroy has exfiltrated encrypted data over the C2 channel using the `up <FILENAME>` command. |
| T1059.003 Windows Command Shell |
HTTPTroy has the ability to generate a reverse shell using the command `conn <IP_ADDRESS> <PORT>`. |
| T1070.004 File Deletion |
HTTPTroy can terminate its running process and then remove traces of itself through the `die <COMMAND>` command. |
| T1071.001 Web Protocols |
HTTPTroy has used HTTP POST requests to communicate with C2. |
| T1105 Ingress Tool Transfer |
HTTPTroy has the ability to download files from C2 using the `down <FILENAME>` command. |
| T1106 Native API |
HTTPTroy has leveraged Windows Native API calls, including `GetProcAddress` to execute functions in memory. |
| T1113 Screen Capture |
HTTPTroy has obtained screen captures leveraging the `screen` command which captures, encrypts and uploads the stolen image to the adversary controlled C2 server. |
| T1132.002 Non-Standard Encoding |
HTTPTroy has obfuscated HTTP POST request communications utilizing XOR with a designated key of 0x56, followed by Base64 encoding. |
| T1140 Deobfuscate/Decode Files or Information |
HTTPTroy has decoded strings encoded with Base64 and XOR prior to execution. |
| T1548.002 Bypass User Account Control |
HTTPTroy has leveraged the ability to execute commands with system privileges using the `srun <EXECUTABLE> <ARGS>` command. |
| T1573.001 Symmetric Cryptography |
HTTPTroy has obfuscated request communications utilizing XOR encryption. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.