Description
HOPLIGHT is malware associated with North Korean threat actors that provides backdoor access and data theft capabilities on infected systems. Researchers tied the family to campaigns that use trojanized applications and proxy tooling to reach targeted networks, and its operators favor long running reconnaissance over rapid monetization. Defenders should treat detections under this name as evidence of targeted activity rather than commodity criminal malware.
Stats
- First seen
- February 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
21 techniques across 9 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Win32.Trojan.Hoplight |
| Win64.Trojan.Hoplight |