Skip to content

Malware

HIGHNOON

According to FireEye, HIGHNOON is a backdoor that may consist of multiple components.

HIGHNOON is a Windows malware family operated by APT41 and Aurora Panda.

Background

FireEye characterizes HIGHNOON as a backdoor built from several pieces, potentially a loader, a DLL, and a rootkit. The loader and DLL are typically dropped at the same time, while the rootkit can be carried inside the DLL. The loader component appears intended to execute as a Windows service.


Source: Malpedia (Fraunhofer FKIE).