#Wolfic

Malware/Tool

2022-12-06 • DEV-0139 launches targeted attacks against the cryptocurrency industry

Wolfic is a Microsoft Defender detection family for downloader components used in a cryptocurrency-themed Lazarus campaign. Variants include TrojanDownloader:O97M/Wolfic.A through .C, TrojanDownloader:Win32/Wolfic.D and .E, and behavioral detections for WolficDownloader. The campaign used a weaponized Excel document with obfuscated macros and UserForm data to drop and execute additional content from a directory under C:\ProgramData, while Defender also associated the activity with DLL search-order hijacking.

Tagged Reports

« Back