logo

TDrop2 Attacks Suggest Dark Seoul Attackers Return - Palo Alto Networks BlogPalo Alto Networks Blog

ID: cac96ebb-0a6c-448a-aa2e-bcb4958dde01

STIX ID: report--cac96ebb-0a6c-448a-aa2e-bcb4958dde01

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2015-11-21

Last Modified Date: 2015-11-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports discovery of a TDrop2 malware campaign (June 2015) that exhibits strong similarities to the 2013 Dark Seoul/Operation Troy toolset. The trojan is delivered via trojanized installers, uses process hollowing and custom string decryption, retrieves second-stage payloads from compromised C2 websites (domains and URLs listed), and targets transportation/logistics in Europe; hashes and IoCs are provided and attribution to the original APT actors is considered likely but not confirmed.