#TAINTEDSCRIBE

Malware/Tool

2020-05-12 • MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE

TAINTEDSCRIBE is a Windows beaconing implant used by Lazarus Group and identified by CISA as North Korean government malware. It masquerades as Microsoft Narrator, copies itself to the current user’s Startup folder for persistence, and retrieves EngineDll.dll command modules from its command-and-control server. The implant uses FakeTLS for session authentication and LFSR encryption for post-handshake traffic. Its modules support file upload, download, deletion, and execution, Windows command-line access, process creation and termination, and host enumeration. It can also compress and exfiltrate files through its modular command set. MITRE ATT&CK S0586.

Tagged Reports

« Back