KingOfHearts
Description
(Kaspersky) In terms of capabilities, KingOfHearts offers nothing more than the basic features you would expect from a backdoor: • Arbitrary command execution • File system manipulation: listing drives and files, deleting, uploading and downloading data, etc. • Listing of running processes with the option to terminate any of them • Capturing screenshots using a custom standalone utility, described below
Rather than developing sophisticated features, the malware developers instead opted to include anti-debugging and virtualization detection routines. Communications with the C2 server take place over HTTP(S), implemented with the wsdlpull open source library. The backdoor looks for new orders every second by sending a heartbeat to the C2 (the “HEART” command, hence the name).
Names
Name |
---|
KingOfHearts |
Category
Malware
Type
- Reconnaissance
- Backdoor
- Info stealer
Information
Other Information
Uuid
c8d96d97-8458-4183-b778-4123781fdc06
Last Card Change
2020-10-19