Loading ATT&CK
HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. HTTPTroy was first reported in October 2025. HTTPTroy has been observed in operations attributed to DPRK-affiliated threat actors, including Kimsuky. HTTPTroy has been delivered to victims through a separate loader leveraged by Kimsuky.(Citation: Gen Digital Kimsuky HTTPTroy October 2025)
Only techniques sit in a kill chain phase.
| Direction | Type | Related object |
|---|---|---|