GBHackers

North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names


North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open‑source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled networks while obscuring the software’s true origin.

ClamAV is a widely used open‑source antivirus engine maintained by the Cisco Talos team, designed for mail gateways, file scanning, and general malware detection across Unix‑like systems.

By leveraging ClamAV’s GPL‑licensed code, North Korean developers could lift a mature detection engine, signature format, and update mechanism, then modify and repurpose it without needing to build an AV stack from scratch.

This is consistent with earlier technical analyses of SiliVaccine, in which researchers found extensive borrowing from third‑party antivirus engines and foreign development practices within North Korea’s security software.

In the latest iteration, North Korea appears to have reconstructed a ClamAV‑based engine and packaged it under at least four different product identities targeted at separate operational environments.

While the binaries share core scanning logic, signature handling, and engine behavior characteristic of ClamAV, each “brand” is positioned as a distinct domestic solution for government, military, research, or enterprise networks.

The motivation is clear: present a home‑grown defensive capability to local stakeholders, while silently inheriting foreign detection technology and maintaining plausible deniability about external dependencies.

The rebranded antivirus variants are marketed as independent security products, but static and behavioral analysis points to a single lineage. The engines preserve ClamAV’s signature taxonomy, including category and platform naming schemes, and follow recognizable patterns for malware families and CVE‑style identifiers.

 ModernStealer (Source : Stealthmole).

Update routines and database file structures also mirror upstream ClamAV behavior, strongly suggesting that North Korea is consuming or cloning portions of existing signature feeds rather than designing original detection content at scale.

From an operational standpoint, these four names serve more as segmentation labels than technical differentiators.

Each variant is likely mapped to a specific customer group defence institutions, government ministries, academic and research networks, or critical industrial systems allowing Pyongyang to present tailored branding and deployment stories while reducing engineering overhead.

Internally, administrators may see them as different products, but the underlying detection capability remains tied to the same repurposed open‑source engine.

Stealthmole Researchers said that, For North Korea, rebuilding ClamAV offers three advantages: rapid access to a functional malware detection stack, lower development cost, and the ability to present indigenous security tools to politically sensitive customers.

For defenders outside the country, however, this reuse raises familiar concerns.

North Korea Rebuilt Its Antivirus

A state that routinely engages in offensive cyber operations is now operating an AV platform whose internals are based on globally recognized open‑source code, creating potential for dual‑use: the same reverse‑engineering efforts that produced these tools can be turned toward bypassing ClamAV‑like defenses elsewhere.

Dark Web Tracker (Source : Stealthmole).
Dark Web Tracker (Source : Stealthmole).

The practice also fits within a broader pattern of underground and state‑linked actors reusing public tooling and infrastructure.

Recent dark‑web investigations into the identity “ModernStealer” show how military and government data offerings are structured around persistent contact artifacts Session IDs, Tox IDs, and Telegram handles rather than unique tooling alone.

Just as those identifiers quietly connect multiple aliases across dark‑web forums and Telegram channels, a ClamAV‑derived engine linked to four different “national” antivirus brands illustrates the same principle in software: different names on top of a shared, largely foreign core.

This reuse of open‑source defensive tooling lands against a backdrop of rapidly expanding markets for military and defence‑related leaks.

Recent threat‑intel reporting has tracked actors offering alleged DARPA material, nuclear regulatory data, and defence research documents on underground forums, often under unverified or inflated claims.

Parallel alerts highlight the sale of strategic projects and restricted defence ministry data, including large DRDO‑related bundles tied to older but still sensitive compromises.

In that ecosystem, tools like StealthMole and other dark‑web monitoring platforms have shown that following contact infrastructure Session IDs, Telegram IDs, and recurring aliases provides more reliable insight than taking seller branding at face value.

The same lesson applies to North Korea’s antivirus story: what matters is not the four different names printed on the product boxes, but the shared ClamAV‑based engine underneath, and the geopolitical calculus driving a state adversary to borrow open‑source security code while projecting self‑reliance at home quietly.

$1M Data Breach Warranty is Genuine Protection?: Download 10 Point Free AI SOC Breach Warranty Guide



Source link