nccTrojan is a remote access trojan (RAT) first documented by Kaspersky in March 2022, attributed to the North Korean advanced persistent threat group APT43 (also tracked as Kimsuky or Thallium). The malware is primarily used for intelligence gathering against South Korean government agencies, defense contractors, and academic research institutions, operating as a backdoor for lateral movement and data exfiltration.
nccTrojan propagates via spear‑phishing emails containing malicious Microsoft Office documents that download a first‑stage PowerShell stager. The stager injects the main payload into legitimate processes (e.g., svchost.exe) using process hollowing (MITRE ATT&CK T1055.012). Communication with command‑and‑control (C2) servers is encrypted over HTTPS (T1568.002), using a custom XOR‑based protocol to blend with normal web traffic. Persistence is achieved through a scheduled task (T1053.005) that re‑launches the payload on system boot. For evasion, the malware checks for sandbox environments by verifying system uptime and installed antivirus products, and it can delete its own registry artifacts after execution.
First spotted in early 2022, nccTrojan was used in a high‑profile campaign targeting the Korea Atomic Energy Research Institute (KAERI) in June 2022, according to a report by the South Korean National Cyber Security Center (NCSC). In November 2022, Microsoft Threat Intelligence linked the same toolset to a series of attacks against nuclear‑related supply chain partners. No specific CVEs are associated with the trojan itself; it exploits macro and OLE vulnerabilities in Microsoft Office (e.g., CVE‑2017‑11882) for initial access.
Known file hashes include SHA‑256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (as published by VirusTotal). Network indicators include C2 domains using dynamic DNS services and User‑Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Behavioral signatures include the creation of scheduled tasks named “WindowsUpdateTask” and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun.
Primary damage includes exfiltration of classified government documents, intellectual property, and research data, leading to potential national security breaches. Financial losses are indirect but significant, with affected organizations incurring remediation costs and operational downtime. Targeted sectors are overwhelmingly government, defense, and nuclear energy in South Korea and Japan.
Organizations should disable macros by default, apply Office patch KB5001912 for legacy vulnerabilities, and deploy EDR solutions with YARA rules for nccTrojan behavior. Microsoft 365 Defender’s “Investigate” module can detect the PowerShell stager through AMSI scanning (MITRE D3‑F‑AMSI).
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.