#Copperhedge
Malware/Tool
Copperhedge, also called Brandoor in the cited reporting, is a Windows backdoor in the Manuscrypt family associated with Lazarus. It functions as a remote access tool able to execute arbitrary commands, survey systems, and steal data. One observed chain used a 32-bit MFC dropper, a DLL loader, and a final Copperhedge-variant backdoor; the dropper required a 34-character argument containing a ChaCha20 key, dynamically resolved APIs, randomized filenames, and added large amounts of junk data to impede scanning. Campaign reporting places Copperhedge after watering-hole, spear-phishing, software-vulnerability, and staged payload activity targeting Korean organizations, including cryptocurrency-related entities.
-
7
Tagged Reports
-
6
Unique Authors
-
2,271
Active Days