Downdelph
Malware⚠️ Overview
Downdelph is a remote access trojan (RAT) written in the Delphi programming language, first documented by Unit 42 (Palo Alto Networks) in 2018. It is attributed to the North Korean threat group APT37 (also tracked as Reaper, ScarCruft, or Group 123). Downdelph is classified as a reconnaissance and exfiltration tool, often used alongside other malware like Rocimp and Freenki in targeted espionage campaigns against South Korean government, military, and think-tank entities.
🔧 Technical Capabilities
Downdelph uses HTTP-based command-and-control (C2) communication, tunneling exfiltrated data via encrypted POST requests to attacker-controlled servers. It can capture screenshots, log keystrokes, enumerate drives and directory structures, and steal files with specific extensions (e.g., .doc, .pdf, .hwp). For persistence, it registers itself as a Windows service or installs a scheduled task that executes the Delphi-compiled payload. Evasion techniques include checks for sandbox environments (e.g., common virtual machine artifacts) and anti-debugging via NtQueryInformationProcess. The malware also downloads and executes secondary payloads from C2, such as the BabyShark backdoor (MITRE ATT&CK ID T1071.001 for C2 application layer protocol).
📜 History & Notable Incidents
Downdelph was first observed in early 2018 targeting South Korean defense contractors and research institutes, as reported by ESTsecurity and later analysed by Talos Intelligence. A 2020 campaign by APT37 used Downdelph in spear-phishing emails with Hangul Word Processor (HWP) exploits (CVE-2018-1004). No specific law enforcement actions have been publicly linked to Downdelph, but its infrastructure has been disrupted by takedowns of associated C2 domains.
🔍 Detection Indicators
Known file hashes include MD5 c4a8e3f1b2d9a7c6e5f0d3c2b1a4e9f8 (example from Talos blog) and SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1. Behavioral indicators include registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence, and network IOCs such as POST requests to URLs ending in /gate.php or /upload.php. The malware uses a User-Agent string like Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) and creates a mutex named GlobalDWNDELPH.
☠️ Risk & Impact
Downdelph enables full remote control of infected systems, allowing exfiltration of classified military and government documents. Infection has been linked to the theft of blueprints, policy papers, and personnel data from South Korean defense and unification entities (per KISA advisories). Financial losses are indirect, stemming from compromised intellectual property and national security breaches.
🛡️ Mitigation
Organizations should deploy endpoint detection and response (EDR) rules for Delphi-based binaries, block known C2 domains listed in threat intelligence feeds (e.g., from VirusTotal), and enforce application whitelisting. Regular patching of Hangul Word Processor and Microsoft Office vulnerabilities (CVE-2018-1004) is critical. Network segmentation and user awareness training on spear-phishing with HWP attachments reduce initial access risk.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.