KURTON is a backdoor that tunnels its connection through a pre-configured proxy. The malware communicates with a remote command and control server over HTTPS via the proxy. The malware installs itself as a Windows service with a service name supplied by the attacker but defaults to IPRIP if no service name is provided during install. ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.59