HTTPTroy
S9007 · Windows
HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. HTTPTroy was first reported in October 2025. HTTPTroy has been observed in operations attributed to DPRK-affiliated threat actors, including Kimsuky.
HTTPTroy has been delivered to victims through a separate loader leveraged by Kimsuky.
ATT&CK S9007
Sigma rules0
YARA rules0
Live IOCs0