Source |
TrendLabs Security |
Identifiant |
459756 |
Date de publication |
2018-01-24 13:56:18 (vue: 2018-01-24 13:56:18) |
Titre |
Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool, an Evolved RATANKBA, and More |
Texte |
We analyzed a new RATANKBA variant (BKDR_RATANKBA.ZAEL.A) that uses a PowerShell script instead of its more traditional PE executable form. In this entry, we provide in-depth analysis of the malware, as well as a detailed examination of its remote controller.
Post from: Trendlabs Security Intelligence Blog - by Trend Micro
Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool, an Evolved RATANKBA, and More
|
Notes |
|
Envoyé |
Oui |
Condensat |
analysis analyzed bkdr blog campaign controller cryptocurrencies depth detailed entry evolved examination executable form from: instead intelligence its lazarus malware micro more new post powershell provide ratankba remote reveals script security targeting tool traditional trend trendlabs uses variant well zael |
Tags |
|
Stories |
APT 38
|
Move |
|