HotCroissant — Malware Profile

HotCroissant is a remote access trojan (RAT) attributed by U.S. government entities to malicious North Korean government cyber activity, tracked collectively as HIDDEN COBRA. HotCroissant shares numerous code similarities with Rifdoor.

MITRE ATT&CK techniques (20)

Attributed threat actors

Read the full analysis on IntelFusions