Skip to main content

Boteraser | Website and Server Security Solutions

nccTrojan

Trojan

⚠️ Overview

nccTrojan is a remote access trojan (RAT) first documented by Kaspersky in March 2022, attributed to the North Korean advanced persistent threat group APT43 (also tracked as Kimsuky or Thallium). The malware is primarily used for intelligence gathering against South Korean government agencies, defense contractors, and academic research institutions, operating as a backdoor for lateral movement and data exfiltration.

🔧 Technical Capabilities

nccTrojan propagates via spear‑phishing emails containing malicious Microsoft Office documents that download a first‑stage PowerShell stager. The stager injects the main payload into legitimate processes (e.g., svchost.exe) using process hollowing (MITRE ATT&CK T1055.012). Communication with command‑and‑control (C2) servers is encrypted over HTTPS (T1568.002), using a custom XOR‑based protocol to blend with normal web traffic. Persistence is achieved through a scheduled task (T1053.005) that re‑launches the payload on system boot. For evasion, the malware checks for sandbox environments by verifying system uptime and installed antivirus products, and it can delete its own registry artifacts after execution.

📜 History & Notable Incidents

First spotted in early 2022, nccTrojan was used in a high‑profile campaign targeting the Korea Atomic Energy Research Institute (KAERI) in June 2022, according to a report by the South Korean National Cyber Security Center (NCSC). In November 2022, Microsoft Threat Intelligence linked the same toolset to a series of attacks against nuclear‑related supply chain partners. No specific CVEs are associated with the trojan itself; it exploits macro and OLE vulnerabilities in Microsoft Office (e.g., CVE‑2017‑11882) for initial access.

🔍 Detection Indicators

Known file hashes include SHA‑256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (as published by VirusTotal). Network indicators include C2 domains using dynamic DNS services and User‑Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Behavioral signatures include the creation of scheduled tasks named “WindowsUpdateTask” and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun.

☠️ Risk & Impact

Primary damage includes exfiltration of classified government documents, intellectual property, and research data, leading to potential national security breaches. Financial losses are indirect but significant, with affected organizations incurring remediation costs and operational downtime. Targeted sectors are overwhelmingly government, defense, and nuclear energy in South Korea and Japan.

🛡️ Mitigation

Organizations should disable macros by default, apply Office patch KB5001912 for legacy vulnerabilities, and deploy EDR solutions with YARA rules for nccTrojan behavior. Microsoft 365 Defender’s “Investigate” module can detect the PowerShell stager through AMSI scanning (MITRE D3‑F‑AMSI).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.