HTTPTroy — Malware Profile

HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. HTTPTroy was first reported in October 2025. HTTPTroy has been observed in operations attributed to DPRK-affiliated threat actors, including Kimsuky. HTTPTroy has been delivered to victims through a separate loader leveraged by Kimsuky.

MITRE ATT&CK techniques (13)

IntelFusions coverage

Attributed threat actors

Read the full analysis on IntelFusions