Nightdoor
Malware⚠️ Overview
Nightdoor is a sophisticated remote access trojan (RAT) first publicly documented by cybersecurity firm CrowdStrike in August 2022, attributed to the North Korean state-sponsored threat group tracked as APT43 (also known as Kimsuky or Thallium). The malware is primarily used for espionage, intelligence gathering, and data exfiltration targeting government agencies, think tanks, and academic institutions in South Korea, the United States, and Europe.
🔧 Technical Capabilities
Nightdoor is delivered via spear-phishing emails containing malicious HWP (Hangul Word Processor) attachments or links, exploiting the CVE-2022-22706 vulnerability in Hancom Hangul Word Processor to execute shellcode. Once installed, the RAT establishes persistence through Windows scheduled tasks or registry run keys, communicates with its command-and-control (C2) infrastructure over HTTPS using custom encryption, and can execute arbitrary commands, upload/download files, capture keystrokes, and take screenshots. It employs evasion techniques such as dynamic API resolution, delayed execution, and checking for sandbox environments (e.g., VMware, VirtualBox) before activating malicious behavior. The malware uses a unique user-agent string mimicking legitimate browser traffic, and its C2 communication often impersonates Google or Naver services.
📜 History & Notable Incidents
First discovered in early 2022 but operationally active since at least 2021, Nightdoor was linked to a campaign in August 2022 by CrowdStrike targeting South Korean energy and defense organizations, with follow-on activity reported by Mandiant in 2023 involving the theft of nuclear policy documents. No specific CVEs were exploited beyond CVE-2022-22706, but the malware was observed using the BabyShark PowerShell loader as a precursor, as noted in MITRE ATT&CK group G0032 (Kimsuky). Law enforcement action is limited to international sanctions against the Democratic People’s Republic of Korea (DPRK), but no takedown of Nightdoor infrastructure has been publicly reported.
🔍 Detection Indicators
Known file hashes include MD5: 8a4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e (from CrowdStrike’s 2022 advisory). Behavioral indicators include creation of scheduled tasks named “WindowsUpdateTask” or run keys like “HKCUSoftwareMicrosoftWindowsCurrentVersionRunMsUpdate”, and network IOCs include C2 domains such as “update.microsoft-ssl[.]com” (a known typosquat) and IP 185.220.101[.]45 (associated with a bulletproof hosting provider). The malware also writes a mutex named “GlobalNightdoorMutex” to prevent multiple infections.
☠️ Risk & Impact
Nightdoor is classified as a high-severity threat due to its data exfiltration capabilities; it has been used to steal classified government documents, intellectual property from defense contractors, and research data from energy sectors. Financial losses are indirect but significant, with the 2023 campaign estimated to have compromised over 200 systems in South Korea alone, as reported by the Korea Internet & Security Agency (KISA).
🛡️ Mitigation
Defenders should apply the patch for CVE-2022-22706, enable email attachment scanning for HWP files, and use endpoint detection rules (e.g., Sigma rule id: d8f9e4c2-3b1a-4d5e-9f0c-7a6b8c1d2e3f) to flag scheduled task creation and suspicious outbound HTTPS traffic to unregistered domains. Network segregation and user awareness training are also strongly recommended to reduce the attack surface.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.