Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Tesla’s fourth “master plan” reads like nonsense generated in LLM

Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe

Humanity raises a $13 billion Series F at a valuation of $183 billion

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe
Identity

Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe

userBy userSeptember 2, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 2, 2025Ravi LakshmananMalware/Threat Intelligence

North Korea-related threat actors known as the Lazarus Group are attributed to a social engineering campaign that distributes three different cross-platform malware, known as Pondrat, Themeforestrat and Remotepe.

The attack observed by NCC Group’s Fox-IT in 2024 targeted organizations in the distributed finance (DEFI) sector, ultimately leading to compromises in the employee system.

“From there, actors made discoveries from within the network using different rats in combination with other tools to harvest credentials and proxy connections, for example,” said Yun Zheng Hu and Mick Koomen. “The actor then moves to stealth rats, which probably means the next stage of the attack.”

The attack chain uses fake websites in which threat actors impersonate existing employees of trading companies on Telegram and schedule meetings with victims under the guise of Calendly and Picktime.

Audit and subsequent

Currently, the exact initial access vector is unknown, but the scaffolding is utilized to deploy a loader called Perfhloader and drop Pondrat, a known malware that has been evaluated as a stripped variant of Poodrat (also known as Simplesea). The cybersecurity company said there is some evidence that suggests that the then zero-day exploit of the Chrome browser is being used in the attack.

It also comes with Pondrat and offers many other tools, including screenshotter, keyloggers, chrome credentials, Cookie Steeler, Mimikatz, FRPC, proxy programs such as MidProxy and Proxy Mini.

“Pont Rat is a simple rat that allows operators to read and write files, start the process and run shellcode,” Fox-It added, dated at least in 2021.

Pondrat malware is designed to communicate over HTTP using a hard-coded command and control (C2) server, and receives further instructions. TheEforStrat boots directly in memory via either Pondrat or a dedicated loader.

Contact the C2 server via HTTP with the new Remote Desktop (RDP) session monitor and new remote desktop (RDP) session monitor to enumerate files/directories, perform file operations, run commands, run commands, perform TCP connections, perform TCP connections, get the file based on DISK, based on TimeESTOMP files based on different files. The amount of time.

CIS Build Kit

Fox-It said Themeforestrat shares similarities with Romeogolf, the malware codename used by the Lazarus group in a destructive wiper attack on Sony Pictures Entertainment (SPE) in November 2014. It was documented by Novetta as part of a collaboration known as Operation Blockbuster.

Remotepe, on the other hand, is retrieved from the C2 server by Remotepeloader and loaded by DPAPILoader. Remotepe written in C++ is a more advanced rat and may be reserved for high value targets.

“The Pondrat is a primitive rat that offers little flexibility, but to achieve its purpose as the first payload,” Fox said. “For more complicated tasks, actors use TheMeforestrat. TheMeforestrat has more features and is loaded only in memory, so it stays under the radar.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHumanity raises a $13 billion Series F at a valuation of $183 billion
Next Article Tesla’s fourth “master plan” reads like nonsense generated in LLM
user
  • Website

Related Posts

Researchers warning MyStrodx backdoor using DNS and ICMP triggers for Stealthy Control

September 2, 2025

An important part of enterprise AI governance

September 2, 2025

Ukrainian Network FDN3 launches massive brute force attacks on SSL VPN and RDP devices

September 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Tesla’s fourth “master plan” reads like nonsense generated in LLM

Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe

Humanity raises a $13 billion Series F at a valuation of $183 billion

WordPress unveils Telex, an experimental AI development tool

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Beyond Compliance: The New Era of Smart Medical Device Software Integration

Unlocking Tomorrow’s Health: Medical Device Integration

Web 3.0’s Promise: What Sir Tim Berners-Lee Envisions for the Future of the Internet

TwinH’s Paves Way at Break The Gap 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.