RaqibCTI
malware

HTTPTroy

S9007 · ATT&CK v19.2
Platforms
Windows
Tracked actors
0

View on attack.mitre.org ↗

Description

[HTTPTroy](https://attack.mitre.org/software/S9007) is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. [HTTPTroy](https://attack.mitre.org/software/S9007) was first reported in October 2025. [HTTPTroy](https://attack.mitre.org/software/S9007) has been observed in operations attributed to DPRK-affiliated threat actors, including [Kimsuky](https://attack.mitre.org/groups/G0094). [HTTPTroy](https://attack.mitre.org/software/S9007) has been delivered to victims through a separate loader leveraged by [Kimsuky](https://attack.mitre.org/groups/G0094).(Citation: Gen Digital Kimsuky HTTPTroy October 2025)

Actors that use this

0 tracked actors
No tracked actor uses this yet
Not linked to any of our tracked MENA actors in actor_software — still browsable via the ATT&CK dictionary above.