S0431Windows

S0431HotCroissant

Platforms
1
ATT&CK
14.1
References
3

Description

[HotCroissant](https://attack.mitre.org/software/S0431) is a remote access trojan (RAT) attributed by U.S. government entities to malicious North Korean government cyber activity, tracked collectively as HIDDEN COBRA.(Citation: US-CERT HOTCROISSANT February 2020) [HotCroissant](https://attack.mitre.org/software/S0431) shares numerous code similarities with [Rifdoor](https://attack.mitre.org/software/S0433).(Citation: Carbon Black HotCroissant April 2020)

Platforms· 1

Windows

References

  1. https://attack.mitre.org/software/S0431
  2. https://www.us-cert.gov/ncas/analysis-reports/ar20-045d
  3. https://www.carbonblack.com/2020/04/16/vmware-carbon-black-tau-threat-analysis-the-evolution-of-lazarus/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Rifdoor
Software
ECCENTRICBANDWAGON
Software
ROKRAT
Software
BLINDINGCAN
Software
HOPLIGHT
Software
KEYMARBLE
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.