Security researchers have discovered a previously unknown backdoor they have dubbed Dolphin, which is being used by North Korean hackers (APT37) in highly targeted attacks. Experts claim that Dolphin has been used for over a year to steal files.

According to research by ESET, the APT37 threat group (also known as Reaper, Red Eyes, Erebus, ScarCruft) used the backdoor against very specific entities. These hackers have been linked to espionage activity consistent with North Korean interests since 2012.
Researchers found Dolphin in April 2021 and noticed that new versions are constantly being created with improved code and mechanisms that make detection more difficult.
See also: How Sudan is connected to the Predator scandal that is shaking Greece
The research showed that Dolphin is used together with BLUELIGHT, a reconnaissance tool that has been detected in previous APT37 malicious campaigns, but has more powerful capabilities such as stealing information from web browsers (passwords), taking screenshots, and recording keystrokes.
BLUELIGHT is used to launch Dolphin's Python loader on a compromised system, but has a limited role in espionage operations.
The Python loader includes a script and a shellcode, initiating multi-step XOR-decryption, process creation, etc. It ends up executing the Dolphin payload in a newly created memory process.
The Dolphin backdoor is a C++ executable that uses Google Drive as a command and control (C2) server and to store stolen files. According to the researchers, the malware creates persistence by modifying the Windows Registry.

Dolphin backdoor capabilities
During the initial stage, Dolphin collects the following information from the infected machine:
- User name
- Computer name
- Local and external IP
- Operating system version
- Installed security software
- RAM size and usage
- Presence of debugging tools or network packet inspection tools
According to security researchers, the backdoor also sends the current configuration, version number, and time to the C2.
See also: Keralty healthcare: Victim of RansomHouse ransomware attack
The configuration contains keylogging and file export instructions, credentials for accessing the Google Drive API, and encryption keys.
Researchers say the hackers delivered their commands to Dolphin by uploading them to Google Drive. In response, the backdoor uploaded the results of executing the commands.
Dolphin backdoor: Stealing files from a connected phone
Its search capabilities extend to any phone connected to the compromised computer using the Windows Portable Device API.
Additionally, it can reduce the security of a victim's Google account by changing related settings. This could allow attackers to maintain access to the victim's account for a longer period of time.
The Dolphin backdoor can record keystrokes in Google Chrome by abusing the “GetAsyncKeyState” API and can take a snapshot of the active window every 30 seconds.
ESET researchers have identified four different versions of the Dolphin backdoor. It is possible that other versions exist and have been used in attacks.
More details can be found in the ESET report
See also: CashRewindo team carries out successful malvertising campaigns
Backdoors are often used by attackers to gain unauthorized access to systems and perform various malicious activities, such as launching additional attacks, stealing sensitive data , or remotely controlling a victim's computers. Backdoors can be difficult to detect and remove once they are installed, which is why it is important for organizations to implement strong security measures that can prevent their installation in the first place.
Source: www.bleepingcomputer.com
