Hodur
- First seen
- 2022-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 13:19:22
Targeted industries: government-and-public-sector energy-and-utilities financial-services
Targeted regions: country_code:us country_code:de
Context
Hodur is a remote access trojan associated with cyber espionage activities, primarily targeting governmental and financial sectors. It is believed to be used by an advanced persistent threat group linked to North Korea.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Hodur_Auto (yara-rule)
Reports & references
- ESET — Mustang Panda Hodur Old Tricks New Korplug Variant (report)
- hitcon.org — Sailing The Seven Seas Deep Dive Into Polaris Arsenal And Intelligence Insights (report)
- github.com — 2024 08 Sailing%20The%20Seven%20Seas (report)
- files.speakerdeck.com — Hodur Recon2024 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Hodur (report)