Korlia

Aliases: Bisonal

First seen
2010-01-01 00:00:00
Malware type
rat, backdoor
Family
Malware family
Profile updated
2026-07-07 12:51:09

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:cn country_code:kr

Context

Korlia, also known as Bisonal, is a remote access trojan primarily used by threat actors for cyber espionage. It is known for targeting governmental and energy sectors in East Asia, with capabilities to execute commands and exfiltrate data.

Reports & references

  • Kaspersky — 97962 (report)
  • sentinelone.com — Targets Of Interest Russian Organizations Increasingly Under Attack By Chinese Apts (report)
  • go.recordedfuture.com — Cta 2023 0919 (report)
  • research.checkpoint.com — Vicious Panda The Covid Campaign (report)
  • Cisco Talos — Bisonal 10 Years Of Play (report)
  • secureworks.com — Bronze Huntley (report)
  • nao-sec.org — An Overhead View Of The Royal Road (report)
  • ptsecurity.com — Winnti 2020 Eng (report)
  • ptsecurity.com — Winnti 2020 Rus (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Korlia (report)
  • jsac.jpcert.or.jp — Jsac2020 3 Takai Jp (report)
  • ptsecurity.com — Winnti Shadowpad (report)
  • web.archive.org — Cle T04 Final V1 (report)
  • global.ahnlab.com — Asec%20Report Vol.93 Eng (report)
  • asec.ahnlab.com — Operation%20Bitter%20Biscuit (report)
  • Palo Alto Unit 42 — Unit42 Bisonal Malware Used Attacks Russia South Korea (report)
  • asec.ahnlab.com — 1298 (report)
  • securitykitten.github.io — Curious Korlia (report)
  • youtube.com — Watch (report)
  • researchcenter.paloaltonetworks.com — Unit42 Bisonal Malware Used Attacks Russia South Korea (report)
  • github.com — 2014 11 25 Curious Korlia.Md (report)
  • slideshare.net — Bsides Ir In Heterogeneous Environment (report)

External references