Skip to main content

Volgmer: North Korean Backdoor Trojan

Volgmer is a backdoor trojan used by the North Korean government (also known as HIDDEN COBRA) since 2013 to provide covert access to a compromised system.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Volgmer is a backdoor trojan used by the North Korean government (also known as HIDDEN COBRA) since 2013 to provide covert access to a compromised system.

Threat details

It has been used to target government, health, financial, automotive, and media industries in multiple countries.

The primary attack vector is believed to be spear-phishing, although is possible that this mechanism may change as the North Korean government maintains a custom suite of tools with which Volgmer could be delivered on to a user’s system. Payloads have been observed as either 32-bit executables or dynamic-link libraries (DLLs), with the malware beaconing to its command and control (C2) server using a custom binary protocol, typically over TCP ports 8080 or 8088. Persistence on a user’s system is achieved by installing a copy of the malware inside a randomly selected service, before overwriting said service’s ServiceDLL entry.

As a backdoor trojan, Volgmer has multiple capabilities including:

  • Gathering system information
  • Updating service registry keys
  • Downloading files
  • Executing and terminating processes

Remediation advice

To prevent and detect a Trojan infection, ensure that:

Remediation steps

Type Step
  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, antivirus and other security products are kept up to date.
  • All day to day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place and password reuse is discouraged.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from infected machines should be reset on a clean computer.

Last edited: 17 February 2020 11:41 am