Troll Stealer is a Go-based infostealer linked in the provided reporting to Kimsuky/SeedpuNK activity. It was discovered in late 2023 to early 2024 and has been described as being distributed through fake or trojanized South Korean security software installation pages, including installers masquerading as SGA Solutions TrustPKI and NX_PRNMAN. The malware is typically installed by a dropper, has been delivered as a VMProtect-packed binary, uses legitimate stolen code-signing certificates, and is dropped as a DLL that is executed via rundll32.exe; one reported chain also executed a legitimate SGA Solutions installer while loading the malicious DLL.
Its primary capability is information theft. Reported collection includes data from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions; all data in victim .ssh folders; FileZilla data; Microsoft Sticky Notes; screenshots; system information; selected files from the C drive; and key material associated with South Korea’s Government Public Key Infrastructure (GPKI). Multiple sources specifically note theft of GPKI certificates and keys from infected devices, including harvesting from the C:\GPKI directory and targeting GPKI-related folders via hashed folder-name comparison. This targeting indicates a focus on South Korean administrative, government, and public institution systems.
For exfiltration, Troll Stealer collects and compresses stolen data, encrypts gathered information on the victim, and sends it to command-and-control infrastructure over HTTP. The reporting states it performs XOR encryption and Base64 encoding prior to transmission, and one source further states it used RC4 and RSA-4096 to encrypt stolen data before HTTP exfiltration. A reported C2 URL is hxxp[:]//qi.limsjo.p-e[.]kr/index.php. The malware has also been associated with use of a valid D2innovation Co., LTD certificate, with the same certificate serial number reportedly reused by GoBear.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In early 2024, a new malware written in Go and labelled Troll Stealer was discovered by S2W. This malware has the ability to steal GPKI (Government Public Key Infrastructure) certificates and keys that are stored on infected devices.
Discovered in January 2024, Troll Stealer is an info-stealer malware that was distributed via a security program download page linked to a specific South Korean website, disguised as installation files for SGA Solutions’ TrustPKI and NX_PRNMAN.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The discovered JSE file drops two additional pieces of malware encoded in Base64 and executes them through PowerShell commands.
APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
Lots of passwords in mnt/hgfs/Desktop/fish_25327/vps20240103.docx . Including E-Mail and VPS passwords (working).
Specifically steals cookie information from Chromium and Firefox-based browsers on the system.
Troll Stealer gathers information from infected systems such as SSH information from the victim's .ssh directory.
Collects network configuration and ARP table information from the compromised system.
Collects a list of currently running processes along with their names and command-line information.
Scans specific paths (Desktop, Downloads, Documents, etc.) for file lists to steal information.
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing malware referenced for its similar GPKI directory data harvesting capability.
Go-based stealer designed to exfiltrate South Korean government GPKI certificates and private keys from infected systems.
A Go-based stealer designed to exfiltrate South Korean government GPKI certificates and keys from infected systems.
A stealer referenced for similarities in system-detail collection and for implementing collection of the C:\GPKI directory; no broader technical description is provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.