Skip to content

Malware

Drokbk

Drokbk stands out for its use of the GitHub platform as part of its C&C infrastructure.

Drokbk is a Windows malware family operated by APT35.

Background

A distinctive trait of Drokbk is that it incorporates GitHub into its C&C infrastructure, which complicates detection and removal since GitHub is not typically regarded as a malicious platform.

Drokbk operations have been attributed to the Iranian APT group Nemesis Kitten, which is thought to deploy the malware for cyberespionage and theft of financial information.


Source: Malpedia (Fraunhofer FKIE).