Executive Summary
HTTPTroy is a heavily obfuscated Windows backdoor used by Kimsuky for persistent collection, command execution over HTTP/S, defense evasion, and stealthy exfiltration. First reported in October 2025, it demonstrates advanced web‑based C&C capabilities typical of DPRK APT groups.
Enhanced Description
HTTPTroy is a sophisticated Windows backdoor first identified in late 2025 and attributed to Democratic People’s Republic of Korea (DPRK)–aligned threat actor Kimsuky. The malware employs extensive obfuscation techniques, packaging its code within multiple layers of encryption and packing to evade signature‑based detection mechanisms used by endpoint protection platforms. Once executed on a target system, HTTPTroy establishes an HTTP/HTTPS‑based command and control (C&C) channel that allows the adversary to issue remote commands, download additional payloads, modify configuration parameters, and exfiltrate stolen data. The backdoor’s functionality is centered around four core capabilities: persistent collection of system identifiers and credentials, covert communication over web protocols, active defense evasion through process injection suppression and anti‑debugging checks, and data exfiltration that blends with legitimate traffic to remain below network monitoring thresholds. While the supplied description does not detail all modules, it confirms the malware’s ability to maintain a foothold on infected hosts and execute arbitrary tasks under the attacker’s direction. HTTPTroy is commonly delivered via a separate loader crafted by Kimsuky, illustrating a two‑stage delivery approach where the initial downloader is typically benign or disguised as legitimate software before fetching the obfuscated backdoor component. The combination of stealthy installation, encrypted C&C, and aggressive data exfiltration mechanisms makes HTTPTroy a high‑value threat in nation‑state targeting campaigns aimed at espionage and industrial sabotage. Defenders should treat HTTPTroy as an advanced persistent threat (APT) tool that can circumvent many traditional detection techniques. Continuous monitoring of outbound HTTPS traffic, coupled with behavioral analytics capable of spotting anomalous web requests from unknown processes, is essential to identify and neutralize this malware before sensitive data is compromised.
Key Capabilities
Recommended Actions
HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. HTTPTroy was first reported in October 2025. HTTPTroy has been observed in operations attributed to DPRK-affiliated threat actors, including Kimsuky. HTTPTroy has been delivered to victims through a separate loader leveraged by Kimsuky.(Citation: Gen Digital Kimsuky HTTPTroy October 2025)