Tropidoor is a backdoor associated with North Korea-linked DeceptiveDevelopment / Contagious Interview activity and distributed as a second-stage payload by BeaverTail in fake recruitment and trojanized coding-challenge campaigns targeting software developers, particularly those involved in cryptocurrency and Web3 projects. Public reporting states that AhnLab observed BeaverTail downloading Tropidoor from malicious Bitbucket projects delivered via recruitment-themed lures, including cases where BeaverTail was embedded as an obfuscated tailwind.config.js file and a downloader DLL such as car.dll or img_layer_generate.dll retrieved an in-memory Tropidoor payload. Tropidoor has been described by ESET as the most sophisticated payload linked to DeceptiveDevelopment so far.
The malware operates as an in-memory backdoor. Upon execution, it decrypts and attempts to connect to multiple command-and-control servers, collects basic system information, generates a random 0x20-byte session key for encrypted communications, encrypts that key with an RSA public key, and transmits both host information and the encrypted key to the C2. Reported protocol details include use of parameters such as tropi2p for system information, gumi for the encrypted key, s_width for a likely session identifier, and letter with the value 400BadRequest for command polling and result return.
Reported capabilities include system reconnaissance, file deletion, file timestamp modification, screenshot capture, file scanning, process execution and termination, address scanning, payload injection or in-memory loading, file compression and exfiltration, drive and file information collection, and configuration management. One command reportedly directly implements built-in Windows commands including schtasks, ping, reg, net, nslookup, and wmic process. Reporting also notes similarity between this functionality and Lazarus-associated LightlessCan.
Multiple sources state that Tropidoor shares substantial code overlap with PostNapTea, a backdoor previously tied to the Lazarus Group and used against South Korean targets in 2022. ESET assessed this overlap as evidence that Tropidoor is likely based on malware developed by more technically advanced actors under the Lazarus umbrella. Reported C2-related indicators include 103.35.190.170/Proxy.php, 86.104.72.247/Proxy.php, 45.8.146.93/proxy/Proxy.php, 86.104.72.247/proxy/Proxy.php, and IPs 135.181.242.24 and 191.96.31.38.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earlier this year, AhnLab malware hunters documented BeaverTail downloading a new backdoor named Tropidoor. And after doing their own analysis on the previously unknown payload, the ESET duo noted that Tropidoor shares large portions of code with PostNapTea.
Earlier this year, AhnLab malware hunters documented BeaverTail downloading a new backdoor named Tropidoor. And after doing their own analysis on the previously unknown payload, the ESET duo noted that Tropidoor shares large portions of code with PostNapTea.
...previously undocumented backdoor called AkdoorTea, along with tools like TsunamiKit and Tropidoor.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple items describe the DPRK/Lazarus “Contagious Interview” campaign using fake recruiters/job listings/interviews (incl. LinkedIn) to lure developers into running malware (e.g., “Sophisticated LinkedIn Recruiting Scam”, “fake AI recruiter”, “Job Offer from the North”).
Tropidoor code supports several Windows commands including ... ping ... net ... nslookup
Tropidoor code supports several Windows commands including ... net (manage network resources and user accounts)...
Tropidoor code supports several Windows commands including ... wmic process (retrieve info about running processes on a Windows system).
In the first communication with the C&C server, the system information obtained above and a random key encrypted with the RSA public key are encoded in Base64 and transmitted through the “tropi2p” and “gumi” parameters... URL Format Description tropi2p=[Info]&gumi=[Key]&s_width=[SessionID]
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware family distributed via recruitment-email lures in DPRK-linked campaigns.
Tool referenced as part of the same DPRK-linked developer-targeting campaign; no further details in excerpt.
Second-stage backdoor assessed as the most sophisticated payload linked to DeceptiveDevelopment; code overlaps with Lazarus-associated PostNapTea, suggesting shared development or reuse.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.