TDrop2 Attacks Suggest Dark Seoul Attackers Return - Palo Alto Networks BlogPalo Alto Networks Blog
ID: cac96ebb-0a6c-448a-aa2e-bcb4958dde01
STIX ID: report--cac96ebb-0a6c-448a-aa2e-bcb4958dde01
Threat Score
78/100
Uploaded: 2026-08-15
Published Date: 2015-11-21
Last Modified Date: 2015-11-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports discovery of a TDrop2 malware campaign (June 2015) that exhibits strong similarities to the 2013 Dark Seoul/Operation Troy toolset. The trojan is delivered via trojanized installers, uses process hollowing and custom string decryption, retrieves second-stage payloads from compromised C2 websites (domains and URLs listed), and targets transportation/logistics in Europe; hashes and IoCs are provided and attribution to the original APT actors is considered likely but not confirmed.
