TightVNC is an open-source VNC remote access tool that appears in the provided reporting as post-compromise tooling rather than a bespoke malware family. The content states it has been used to allow remote access on victim systems and is listed among tools associated with North Korea-linked activity, including Kimsuky and BlueNorOff/Lazarus-related reporting. In the Kimsuky context, TightVNC is identified as one of several remote-control tools that attackers can install after initial compromise via backdoors such as AppleSeed and PebbleDash. The broader reporting also explicitly describes the use of VNC software such as TightVNC for remote access. High-confidence details in the content do not specify unique infection vectors, persistence mechanisms, or indicators of compromise specific to TightVNC itself beyond its use as remote administration software in intrusion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
10 distinct techniques documented for this family, organized by ATT&CK tactic.
“TightVNC… ‘Password’=hex… VNC uses the same hardcoded DES key… we decrypt it… openssl enc -des-cbc… output ‘sT333ve2’” | “Meeting_Notes_June_2018.html… ‘Username is TempAdmin (password is the same as the normal admin account password)’… VNC Install.reg… ‘Password’=hex… decrypt it… Audit.db… SELECT * FROM Ldap… decompile CascAudit.exe… hardcoded key/IV…”
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access software listed as associated with BlueNorOff operations.
Remote access software referenced as being used for remote services/lateral movement in ransomware intrusions.
Remote access tool listed as post-infection malware/tooling used for remote control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.