Threat actors operating under the control of the North Korean are constantly evolving, introducing advanced malwaredesigned to create persistent backdoor access and remote control over compromised systems. Two of the most prominent groups doing this are Kimsuky and Lazarus.

Recent findings revealed that the Kimsuky, known for organizing espionage, developed HttpTroy, while the Lazarus introduced an improved variant of BLINDINGCAN. These developments highlight the ongoing evolution of government cyber operations targeting organizations in multiple countries.
The campaigns reveal a carefully orchestrated approach, starting with deceptive delivery mechanisms and progressing through multiple infection stages. Each component within these malware chains serves a distinct purpose, from initial system compromise to establishing invisible command and control communications.
See also: Russian Ransomware Groups Abuse AdaptixC2 for Attacks
The infrastructure supporting these operations uses sophisticated obfuscation techniques and multi-layered encryption protocols, demonstrating a comprehensive understanding of modern defense measures and detection systems.
Kimsuky and Lazarus: Different approaches to attacks
Gendigital analysts observed a Kimsuky attack targeting a victim in South Korea , starting with a ZIP file pretending to be a VPN invoice from a legitimate Korean security company. The scam proved effective, as the innocent filename encouraged the execution of a malicious screensaver file (which was embedded).

The Lazarus operation , by contrast, targeted two Canadian entities , incorporating newer techniques for concealing payload delivery and establishing service-based persistence mechanisms that evade traditional endpoint detection approaches. The complexity evident in these campaigns reflects distinct operational patterns attributed to each group.
Kimsuky's attack leveraged social engineering based on the Korean language and scheduled task naming conventions consistent with local antivirus software, creating system activities that sounded convincing. Lazarus used more complex service enumeration and dynamic registry manipulation, suggesting targeting enterprise infrastructure, where legitimate system services provide effective cover for malicious operations.
See also: Malware targets WooCommerce sites and steals credit card data
Infection mechanism and persistence
Kimsuky 's campaign used a three-stage infection chain , starting with a lightweight GO-based dropper containing three embedded files encrypted with XOR operations. When executed, the dropper displays a deceptive PDF invoice while simultaneously establishing the backdoor infrastructure via COM server registration via regsvr32.exe .
The second stage, identified as Memload_V3, creates scheduled tasks that mimic antivirus updates AhnLab, repeating every minute to maintain persistence. Gendigital researchers noted that HttpTroy is the final payload, giving attackers complete control capabilities, including file management, screenshot capture, elevated command execution, and reverse shell deployment.
The backdoor communicates exclusively via HTTP POST requests, implementing two-layer obfuscation consisting of XOR encryption (with key 0x56) followed by Base64 encoding.
See also: Malicious Android apps exploit NFC to steal banking credentials

This communication protocol allows attackers to receive commands formatted as simple “command parameter” structures, while reporting the execution status via specific identifiers. Successful operations are confirmed via “ok” responses and failed attempts are indicated via “fail” messages.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The malware's architecture incorporates dynamic API hashing and runtime string reconstruction techniques , preventing static analysis while complicating detection mechanisms deployed by security organizations that monitor for known malware signatures and behavioral cues.
