Hodur

First seen
2022-01-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 13:19:22

Targeted industries: government-and-public-sector energy-and-utilities financial-services

Targeted regions: country_code:us country_code:de

Context

Hodur is a remote access trojan associated with cyber espionage activities, primarily targeting governmental and financial sectors. It is believed to be used by an advanced persistent threat group linked to North Korea.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Hodur_Auto (yara-rule)

Reports & references

  • ESET — Mustang Panda Hodur Old Tricks New Korplug Variant (report)
  • hitcon.org — Sailing The Seven Seas Deep Dive Into Polaris Arsenal And Intelligence Insights (report)
  • github.com — 2024 08 Sailing%20The%20Seven%20Seas (report)
  • files.speakerdeck.com — Hodur Recon2024 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Hodur (report)

External references