#Manuscrypt

Malware/Tool

2017-12-31 • Never Let Your Infrastructure Go Malicious: Digging Into C&C Infrastructure of Lazarus

Manuscrypt is a full-featured Lazarus backdoor used since at least 2013 across more than fifty campaigns against government, diplomatic, financial, defense, cryptocurrency, technology, gaming, media, academic, and security-research targets. Delivery included malicious HWP documents whose EPS exploit and shellcode downloaded XOR-encoded payloads, often using cryptocurrency or financial decoys and WordPress paths as hosting or C2 locations. In a 2024 Russian case, a fraudulent DeFi NFT tank-game website launched a Chrome zero-day exploit before Manuscrypt was detected.

Tagged Reports

« Back