#OpenCarrot

Malware/Tool

2023-08-07 • Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company

OpenCarrot is a Windows backdoor previously associated with Lazarus activity. SentinelLabs found it inside the network of a sanctioned Russian missile-engineering organization after North Korean-linked actors compromised sensitive internal infrastructure, including an email server. The backdoor's presence helped correlate separate intrusion clusters operating against the same victim and showed that multiple North Korean-linked activities had reached the organization's environment. OpenCarrot served as a remote-access component within this broader espionage intrusion targeting strategically sensitive missile technology.

Tagged Reports

« Back