#PowerRatankba
Incident/Operation
PowerRatankba is a PowerShell-based reconnaissance and first-stage implant used in financially motivated campaigns attributed with high confidence by Proofpoint to Lazarus Group. Activity documented from June 2017 used targeted spearphishing, malicious shortcuts and help files, script downloaders, macro documents, and backdoored cryptocurrency applications. After infection, PowerRatankba profiled the host and reported system, network, process, and language details over HTTP so operators could select victims for additional payloads. Later variants could execute commands, download or inject code, change polling intervals, and deploy a more capable backdoor, including Gh0st RAT, against cryptocurrency-related targets.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days