KingOfHearts

Description

(Kaspersky) In terms of capabilities, KingOfHearts offers nothing more than the basic features you would expect from a backdoor: • Arbitrary command execution • File system manipulation: listing drives and files, deleting, uploading and downloading data, etc. • Listing of running processes with the option to terminate any of them • Capturing screenshots using a custom standalone utility, described below

Rather than developing sophisticated features, the malware developers instead opted to include anti-debugging and virtualization detection routines. Communications with the C2 server take place over HTTP(S), implemented with the wsdlpull open source library. The backdoor looks for new orders every second by sending a heartbeat to the C2 (the “HEART” command, hence the name).

Names

Name
KingOfHearts

Category

Malware

Type

  • Reconnaissance
  • Backdoor
  • Info stealer

Information

Other Information

Uuid

c8d96d97-8458-4183-b778-4123781fdc06

Last Card Change

2020-10-19