#NukeSped

Malware/Tool

2019-10-23 • A Deep-Dive Analysis of the NukeSped RATs

NukeSped is a backdoor family associated with North Korean threat activity, including Lazarus, BlueNoroff, and Andariel reporting. A VBScript variant collected host, user, operating-system, CPU, time-zone, network, process, browser-extension, and Telegram Web data, while supporting in-memory script execution, file download and launch, termination, and task-status reporting through C2. Delivery contexts included fake Zoom or Teams meetings and ClickFix commands aimed at cryptocurrency and Web3 personnel, deployment through a compromised patch-management provider, attacks on exposed Apache ActiveMQ servers potentially exploiting CVE-2023-46604, and abuse of an asset-management program. Another reported operation used NukeSped against maritime research organizations for commercial-secret theft.

Tagged Reports

« Back