1
Groups Using This
1
Platforms
127
Prevalence Rank
0
Known Aliases
Description

HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. HTTPTroy was first reported in October 2025. HTTPTroy has been observed in operations attributed to DPRK-affiliated threat actors, including Kimsuky. HTTPTroy has been delivered to victims through a separate loader leveraged by Kimsuky.

View MITRE record ↗

Platforms
Windows
↑