#Manuscrypt
Malware/Tool
2017-08-24 • A Deep Dive into the Digital Weapons of the North Korean Cyber Army
Manuscrypt is a full-featured Lazarus backdoor used since at least 2013 across more than fifty campaigns against government, diplomatic, financial, defense, cryptocurrency, technology, gaming, media, academic, and security-research targets. Delivery included malicious HWP documents whose EPS exploit and shellcode downloaded XOR-encoded payloads, often using cryptocurrency or financial decoys and WordPress paths as hosting or C2 locations. In a 2024 Russian case, a fraudulent DeFi NFT tank-game website launched a Chrome zero-day exploit before Manuscrypt was detected.
-
12
Tagged Reports
-
7
Unique Authors
-
2,618
Active Days