Names | Hawup Hawup RAT | |
Category | Malware | |
Type | Backdoor | |
Description | (CrowdStrike) Falcon Intelligence identified the file as a Hawup RAT binary attributed to LABYRINTH CHOLLIMA, an adversary believed to conduct espionage operations in support of DPRK intelligence requirements. Once executed, the RAT called out to C2 IP addresses waiting for a response. | |
Information | <https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2018GlobalThreatReport.pdf> |
Last change to this tool card: 20 April 2020
Download this tool card in JSON format
Previous: Havoc
Next: hcdLoader
Changed | Name | Country | Observed | ||
APT groups | |||||
Lazarus Group, Hidden Cobra, Labyrinth Chollima | 2007-Sep 2024 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |