CoreDN

Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 14:54:38

Context

CoreDN is a persistent malware known for its ability to establish backdoor access on compromised systems. It has been utilized in various attacks but lacks a specific industry or region of focus, potentially making it a versatile tool in the hands of threat actors.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Coredn_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Coredn (report)
  • McAfee — Lazarus Resurfaces Targets Global Banks Bitcoin Users (report)
  • blog.alyac.co.kr — 2105 (report)
  • Broadcom/Symantec — 2018 021216 4405 99 (report)
  • McAfee — Lazarus Resurfaces Targets Global Banks Bitcoin Users (report)
  • Cisco Talos — Fake Korean Job Posting (report)

External references