HARDRAIN is malware associated with North Korean government cyber operations tracked by the U.S. government as HIDDEN COBRA. It has been documented as a toolset comprising Windows proxy malware and an Android remote access component. The Windows variants are 32-bit executables that turn compromised systems into proxy servers, open the local firewall to permit inbound access, and bind to TCP port 443. Their command-and-control traffic is disguised with a FakeTLS technique that imitates TLS/SSL sessions using embedded public certificate material while relying on a different underlying encryption method. This design supports covert relay of operator traffic through victim infrastructure and can help obscure command-and-control activity within commonly allowed network flows.
The Android component is an ELF ARM executable described as a fully functioning remote access trojan. Across the documented HARDRAIN set, the malware is intended to maintain presence on victim networks and support further exploitation. The Windows proxy functionality is particularly suited to post-compromise operations by enabling infected hosts to act as intermediary relay nodes for attacker communications. Observed behavior includes use of the Windows command shell to invoke firewall changes that facilitate inbound connectivity.
HARDRAIN has been publicly linked to DPRK intrusion activity spanning at least the late 2010s and is part of a broader ecosystem of Lazarus or HIDDEN COBRA malware that uses network evasion techniques such as FakeTLS and proxying to conceal operations. High-confidence reporting ties it to North Korean government activity rather than financially motivated commodity malware distribution. The available facts directly support Windows and Android targeting, proxy-server behavior, remote access functionality on Android, firewall modification, and defense-evasive command-and-control masquerading.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HIDDEN COBRA - North Korean Malicious Cyber Activity HARDRAIN HARDRAIN
7 distinct techniques documented for this family, organized by ATT&CK tactic.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT and proxy tool set with Android support.
North Korean-linked malware family also described as Android malware in Lazarus-related reporting.
Uses FakeTLS to disguise C2 communications.
Backdoor that changes Windows Firewall configuration to allow/modify inbound connectivity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.