Hawup

Description

(CrowdStrike) Falcon Intelligence identified the file as a Hawup RAT binary attributed to LABYRINTH CHOLLIMA, an adversary believed to conduct espionage operations in support of DPRK intelligence requirements. Once executed, the RAT called out to C2 IP addresses waiting for a response.

Names

Name
Hawup
Hawup RAT

Category

Malware

Type

  • Backdoor

Information

Other Information

Uuid

aa885b8f-3a91-4573-afa6-64178c72f35d

Last Card Change

2020-04-20