North Korean Hackers Spreading Trojanized Versions of PuTTY Client Application

Share:

A threat with a North Korea nexus has been found leveraging a “novel spear phish methodology” that involves making use of trojanized versions of the PuTTY SSH and Telnet client.

Google-owned threat intelligence firm Mandiant attributed the new campaign to an emerging threat cluster it tracks under the name UNC4034.

“UNC4034 established communication with the victim over WhatsApp and lured them to download a malicious ISO package regarding a fake job offering that led to the deployment of the AIRDRY.V2 backdoor through a trojanized instance of the PuTTY utility,” Mandiant researchers said.

The utilization of fabricated job lures as a pathway for malware distribution is an oft-used tactic by North Korean state-sponsored actors, including the Lazarus Group, as part of an enduring campaign called Operation Dream Job.

The entry point of the attack is an ISO file that masquerades as an Amazon Assessment as part of a potential job opportunity at the tech giant. The file was shared over WhatApp after establishing initial contact over email.

The archive, for its part, holds a text file containing an IP address and login credentials, and an altered version of PuTTY that, in turn, loads a dropper called DAVESHELL, which deploys a newer variant of a backdoor dubbed AIRDRY.

It’s likely that the threat actor convinced the victim to launch a PuTTY session and use the credentials provided in the TXT file to connect to the remote host, effectively activating the infection.

AIRDRY, also known as BLINDINGCAN, has in the past been used by North Korea-linked hackers to strike U.S. defense contractors and entities in South Korea and Latvia.

While earlier versions of the malware came with nearly 30 commands for file transfer, file management, and command execution, the latest version has been found to eschew the command-based approach in favor of plugins that are downloaded and executed in memory.

Mandiant said it was able to contain the compromise before any further post-exploitation activities could take place following the deployment of the implant.

The development is yet another sign that the use of ISO files for initial access is gaining traction among threat actors to deliver both commodity and targeted malware.

The shift is also attributable to shoppingmode Microsoft‘s decision to block Excel 4.0 (XLM or XL4) and Visual Basic for Applications (VBA) macros for Office apps downloaded from the internet by default.

https://thehackernews.com/2022/09/north-korean-hackers-spreading.html?

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:15 pm, Jul 8, 2025
weather icon 19°C
L: 17° | H: 21°
overcast clouds
Humidity: 49 %
Pressure: 1019 mb
Wind: 3 mph N
Wind Gust: 6 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 85%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:53 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
17° | 21°°C 0.18 mm 18% 7 mph 57 % 1022 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 9 mph 73 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 8 mph 64 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 9 mph 69 % 1017 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 18°°C 0 mm 0% 3 mph 49 % 1019 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 16°°C 0 mm 0% 3 mph 50 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 5 mph 56 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 5 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 6 mph 55 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
25° | 25°°C 0.18 mm 18% 7 mph 45 % 1021 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 7 mph 44 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 3 mph 53 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,709.14
0.70%
Ethereum(ETH)
€2,220.17
2.67%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.96
1.41%
Solana(SOL)
€128.19
1.19%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145117
1.95%
Shiba Inu(SHIB)
€0.000010
2.58%
Pepe(PEPE)
€0.000009
3.37%
Scroll to Top