#PowerRatankba

Incident/Operation

2017-12-19 • North Korea Bitten by Bitcoin Bug: Financially motivated campaigns reveal new dimension of the Lazarus Group

PowerRatankba is a PowerShell-based reconnaissance and first-stage implant used in financially motivated campaigns attributed with high confidence by Proofpoint to Lazarus Group. Activity documented from June 2017 used targeted spearphishing, malicious shortcuts and help files, script downloaders, macro documents, and backdoored cryptocurrency applications. After infection, PowerRatankba profiled the host and reported system, network, process, and language details over HTTP so operators could select victims for additional payloads. Later variants could execute commands, download or inject code, change polling intervals, and deploy a more capable backdoor, including Gh0st RAT, against cryptocurrency-related targets.

Tagged Reports

« Back