Netskope Threat Labs

HOPLIGHT

ATP Sandbox Adv. HeuristicsNetskope IPS

HOPLIGHT is malware associated with North Korean threat actors that provides backdoor access and data theft capabilities on infected systems. Researchers tied the family to campaigns that use trojanized applications and proxy tooling to reach targeted networks, and its operators favor long running reconnaissance over rapid monetization. Defenders should treat detections under this name as evidence of targeted activity rather than commodity criminal malware.

First seen
February 2022
Last seen
October 2026

21 techniques across 9 tactics.

TA0002 Execution

TA0004 Privilege Escalation

  • T1546Event Triggered Execution
    • T1546.003Windows Management Instrumentation Event Subscription

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1012Query Registry
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1124System Time Discovery
  • T1652Device Driver Discovery
  • T1680Local Storage Discovery

TA0008 Lateral Movement

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

  • T1112Modify Registry
  • T1686Disable or Modify System Firewall
Alert Name
Win32.Trojan.Hoplight
Win64.Trojan.Hoplight