Volgmer: North Korean Backdoor Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The primary attack vector is believed to be spear-phishing, although is possible that this mechanism may change as the North Korean government maintains a custom suite of tools with which Volgmer could be delivered on to a user’s system. Payloads have been observed as either 32-bit executables or dynamic-link libraries (DLLs), with the malware beaconing to its command and control (C2) server using a custom binary protocol, typically over TCP ports 8080 or 8088. Persistence on a user’s system is achieved by installing a copy of the malware inside a randomly selected service, before overwriting said service’s ServiceDLL entry.
As a backdoor trojan, Volgmer has multiple capabilities including:
- Gathering system information
- Updating service registry keys
- Downloading files
- Executing and terminating processes
Remediation advice
To prevent and detect a Trojan infection, ensure that:Remediation steps
Last edited: 17 February 2020 11:41 am