BestKorea

First seen
2016-05-20 00:00:00
Malware type
trojan, backdoor
Family
Malware family
Profile updated
2026-07-07 14:49:02

Targeted industries: government-and-public-sector financial-services

Targeted regions: country_code:kr country_code:us

Context

BestKorea is a state-sponsored malware linked to North Korean threat actors, primarily used for cyber-espionage against government and financial sectors. It functions as a trojan and backdoor, allowing attackers to stealthily access compromised systems.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Bestkorea (report)
  • github.com — Bestkorea (report)

External references