#PseudoManuscrypt

Malware/Tool

2021-12-16 • PseudoManuscrypt: a mass-scale spyware attack campaign

PseudoManuscrypt is spyware identified by Kaspersky ICS CERT in June 2021 during a mass-scale campaign. Its loader resembles Manuscrypt, a family associated with the Lazarus arsenal, but PseudoManuscrypt was tracked as a separate family and was not assigned the same attribution. A malware-as-a-service distribution platform delivered the loader to user systems. Its data-exfiltration channel implemented the KCP protocol, a design previously observed in APT41 tooling, while the campaign reached a broader victim population than the defense-focused targeting associated with Manuscrypt.

Tagged Reports

« Back