Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:45:09 UTC Home > List all groups > List all tools > List all groups using tool KingOfHearts Tool: KingOfHearts Names KingOfHearts Category Malware Type Reconnaissance, Backdoor, Info stealer Description (Kaspersky) In terms of capabilities, KingOfHearts offers nothing more than the basic features you would expect from a backdoor: • Arbitrary command execution • File system manipulation: listing drives and files, deleting, uploading and downloading data, etc. • Listing of running processes with the option to terminate any of them • Capturing screenshots using a custom standalone utility, described below Rather than developing sophisticated features, the malware developers instead opted to include anti-debugging and virtualization detection routines. Communications with the C2 server take place over HTTP(S), implemented with the wsdlpull open source library. The backdoor looks for new orders every second by sending a heartbeat to the C2 (the “HEART” command, hence the name). Information Last change to this tool card: 19 October 2020 Download this tool card in JSON format All groups using tool KingOfHearts Changed Name Country Observed APT groups IAmTheKing 2018 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c8d96d97-8458-4183-b778-4123781fdc06 Page 1 of 2 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c8d96d97-8458-4183-b778-4123781fdc06 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c8d96d97-8458-4183-b778-4123781fdc06 Page 2 of 2