HTTPTroy — Malware Profile
HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. HTTPTroy was first reported in October 2025. HTTPTroy has been observed in operations attributed to DPRK-affiliated threat actors, including Kimsuky. HTTPTroy has been delivered to victims through a separate loader leveraged by Kimsuky.
MITRE ATT&CK techniques (13)
- T1027 Obfuscated Files or Information
- T1027.007 Dynamic API Resolution
- T1041 Exfiltration Over C2 Channel
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1113 Screen Capture
- T1132.002 Non-Standard Encoding
- T1140 Deobfuscate/Decode Files or Information
- T1548.002 Bypass User Account Control
- T1573.001 Symmetric Cryptography