#ThemeForestRAT

Malware/Tool

2025-09-01 • Three Lazarus RATs coming for your cheese

ThemeForestRAT is a remote-access trojan used for at least six years by a Lazarus subgroup targeting financial and cryptocurrency organizations. In 2024 incidents, it operated alongside PondRAT: PondRAT remained on disk while ThemeForestRAT appeared to execute only in memory. Initial access relied on social engineering, including fake meeting and scheduling sites in related activity. Investigators later observed the actor removing PondRAT and ThemeForestRAT artifacts and installing the more advanced RemotePE framework, potentially representing a subsequent stage of the intrusion.

Tagged Reports

« Back