RealTimeTroy is a Go-based backdoor associated with the North Korea-linked BlueNoroff cluster, also tracked as Sapphire Sleet/APT38, and observed in the SnatchCrypto operation’s GhostCall and GhostHire campaigns. It has been deployed on both macOS and Windows, including as a payload delivered by the DownTroy loader and, in some cases, injected via GillyInjector. The malware communicates with command-and-control infrastructure over WSS; Windows reporting additionally notes RC4-encrypted and base64-encoded communications. Reported capabilities include command execution, collection of device/host information, file read/write and upload/download operations, process management including terminating specified processes, and process/PE injection. RealTimeTroy was observed among payloads used against blockchain/Web3 targets, including developers, executives, and managers, with campaigns using social-engineering lures such as fake Zoom or Microsoft Teams meetings and recruiter/coding-assessment themes delivered via Telegram, phishing sites, GitHub repositories, and malicious Go packages. It has been documented as part of broader BlueNoroff tooling alongside DownTroy, CosmicDoor, RooTroy, and SilentSiphon.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RealTimeTroy is a straightforward backdoor written in the Go programming language that communicates with a C2 server using the WSS protocol.
RealTimeTroy ... injects a Go backdoor called RealTimeTroy that communicates with an external server using the WSS protocol to read/write files ... upload/download files, terminate a specified process, and get device information.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
GillyInjector employs a technique known as Task Injection... designed to run a benign Mach-O app and inject a malicious payload into it at runtime... DownTroy.Windows would retrieve a base64-encoded binary blob... and inject it into the cmd.exe process... RealTimeTroy... injects the payload received from the C2.
GillyInjector employs a technique known as Task Injection... designed to run a benign Mach-O app and inject a malicious payload into it at runtime... DownTroy.Windows would retrieve a base64-encoded binary blob... and inject it into the cmd.exe process... RealTimeTroy... injects the payload received from the C2.
RooTroy collects and lists all mounted volumes and running processes... SneakMain.macOS constructs a JSON object containing this information, along with additional fields such as... process list... SysPhon... Process list ps aux.
all three DownTroy strains collect comprehensive system information including OS details, domain name, host name, username, proxy settings, and VM detection alongside process lists... SysPhon... conduct system reconnaissance by executing a series of commands.
"...RealTimeTroy... communicates with an external server using the WSS protocol..."
The main feature of CosmicDoor is that it communicates with the C2 server using the WSS protocol... RealTimeTroy is a straightforward backdoor written in the Go programming language that communicates with a C2 server using the WSS protocol.
DownTroy would download ZIP files that contain various individual infection chains from the actor’s centralized file hosting server... When both the url and auth fields are present, RooTroy connects to the URL... to retrieve additional files.
The main feature of CosmicDoor is that it communicates with the C2 server using the WSS protocol, and it provides remote control functionality such as receiving and executing commands... SneakMain... receives additional AppleScript commands and uses the osascript -e command to execute them.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A payload used on macOS and Windows in BlueNoroff’s GhostCall/GhostHire campaigns, delivered via DownTroy/ZIP-based delivery.
A backdoor used by BlueNoroff in the GhostCall/GhostHire campaigns to maintain access to victim systems.
Go-based backdoor with WSS-based C2 supporting file operations (read/write/upload/download), process control (including termination), and host information collection.
A Go-based backdoor for macOS and Windows that communicates over WSS, executes commands, supports file download and process injection, and can be delivered through GillyInjector or RooTroy chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.