Endoor is a backdoor malware family reported by AhnLab ASEC in campaigns targeting South Korean users via trojanized installers for required login/security software distributed through a Korean construction-related association website. In the observed supply-chain-style compromise, malicious installers such as NX_PRNMAN (mid-January 2024) and previously TrustPKI (December 2023) installed legitimate software alongside malware placed in %APPDATA%, with execution via rundll32.exe. ASEC stated that some infections deployed backdoor malware in addition to the TrollAgent infostealer, and specifically noted the actor used Endoor backdoor strains developed in GoLang with a similar form to previously documented backdoors. The backdoor was described as capable of receiving commands from an external C2 server and being used to download additional malware, including malware that steals screenshots. ASEC reported the backdoor’s C2 command branching resembled backdoors discussed in prior AppleSeed distribution and Kimsuky-related reporting, and a separate 360CERT weekly report stated Kimsuky distributed installer-disguised malware to South Korean public institutions that created the Endoor backdoor. The malicious installers and most installed malware were packed with VMProtect and signed with a valid certificate attributed to D2Innovation, which ASEC assessed was likely stolen. ASEC estimated more than 3,000 infections. Reported related IOCs included MD5 hashes 013c4ee2b32511b11ee9540bb0fdb9d1, 035cf750c67de0ab2e6228409ac85ea3, 19c2decfa7271fa30e48d4750c1d18c1, 27ef6917fe32685fdf9b755eb8e97565, and 2aaa3f1859102aab35519f0d4c1585dd, and C2/URL indicators http[:]//ai[.]aerosp[.]p-e[.]kr/index[.]php, http[:]//ai[.]bananat[.]p-e[.]kr/index[.]php, http[:]//ai[.]daysol[.]p-e[.]kr/index[.]php, http[:]//ai[.]kimyy[.]p-e[.]kr/index[.]php, and http[:]//ai[.]kostin[.]p-e[.]kr/index[.]php.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor created by an implant used in campaigns targeting South Korean public institutions; used to download additional malware and enable follow-on capabilities (e.g., screenshot theft).
GoLang-based backdoor used alongside the TrollAgent infostealer; receives C2 commands to perform attacker-directed actions on infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.