Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 16:12:48 UTC Home > List all groups > List all tools > List all groups using tool Killua Tool: Killua Names Killua Category Malware Type Backdoor Description (Palo Alto) The otc.dll file is a tool named Killua that is a simple backdoor that allows an actor to issue commands from a C2 server to run on the infected system by communicating back and forth using DNS tunneling. Based on string comparisons, we believe with high confidence that the same developer created both the Killua and Hisoka tools. Information Last change to this tool card: 29 April 2020 Download this tool card in JSON format All groups using tool Killua Changed Name Country Observed APT groups xHunt 2018-Aug 2019 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6d31fd01-df9b-4aaf-b8ae-0212f41c3543 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6d31fd01-df9b-4aaf-b8ae-0212f41c3543 Page 1 of 1