Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Stand-up comic goes on extensive tour with Frank Sinatra

Your daily horoscope: June 18, 2026

Learn piano with AI feedback — a lifetime subscription to Skoove is $99.97

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe
Celebrities

Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe

By September 2, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 2, 2025Ravi LakshmananMalware/Threat Intelligence

North Korea-related threat actors known as the Lazarus Group are attributed to a social engineering campaign that distributes three different cross-platform malware, known as Pondrat, Themeforestrat and Remotepe.

The attack observed by NCC Group’s Fox-IT in 2024 targeted organizations in the distributed finance (DEFI) sector, ultimately leading to compromises in the employee system.

“From there, actors made discoveries from within the network using different rats in combination with other tools to harvest credentials and proxy connections, for example,” said Yun Zheng Hu and Mick Koomen. “The actor then moves to stealth rats, which probably means the next stage of the attack.”

The attack chain uses fake websites in which threat actors impersonate existing employees of trading companies on Telegram and schedule meetings with victims under the guise of Calendly and Picktime.

Audit and subsequent

Currently, the exact initial access vector is unknown, but the scaffolding is utilized to deploy a loader called Perfhloader and drop Pondrat, a known malware that has been evaluated as a stripped variant of Poodrat (also known as Simplesea). The cybersecurity company said there is some evidence that suggests that the then zero-day exploit of the Chrome browser is being used in the attack.

It also comes with Pondrat and offers many other tools, including screenshotter, keyloggers, chrome credentials, Cookie Steeler, Mimikatz, FRPC, proxy programs such as MidProxy and Proxy Mini.

“Pont Rat is a simple rat that allows operators to read and write files, start the process and run shellcode,” Fox-It added, dated at least in 2021.

Pondrat malware is designed to communicate over HTTP using a hard-coded command and control (C2) server, and receives further instructions. TheEforStrat boots directly in memory via either Pondrat or a dedicated loader.

Contact the C2 server via HTTP with the new Remote Desktop (RDP) session monitor and new remote desktop (RDP) session monitor to enumerate files/directories, perform file operations, run commands, run commands, perform TCP connections, perform TCP connections, get the file based on DISK, based on TimeESTOMP files based on different files. The amount of time.

CIS Build Kit

Fox-It said Themeforestrat shares similarities with Romeogolf, the malware codename used by the Lazarus group in a destructive wiper attack on Sony Pictures Entertainment (SPE) in November 2014. It was documented by Novetta as part of a collaboration known as Operation Blockbuster.

Remotepe, on the other hand, is retrieved from the C2 server by Remotepeloader and loaded by DPAPILoader. Remotepe written in C++ is a more advanced rat and may be reserved for high value targets.

“The Pondrat is a primitive rat that offers little flexibility, but to achieve its purpose as the first payload,” Fox said. “For more complicated tasks, actors use TheMeforestrat. TheMeforestrat has more features and is loaded only in memory, so it stays under the radar.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHumanity raises a $13 billion Series F at a valuation of $183 billion
Next Article See what happens to Tokyo if Mt. Fuji erupts “without warning” in a video generated by a new AI

Related Posts

The meaning behind Michelle Obama’s vintage photo skirt

June 17, 2026

Angelina Jolie updates her ‘recession blonde’ look in New York City

June 17, 2026

Duchess Kate goes from butter yellow to marigold at Royal Ascot

June 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Stand-up comic goes on extensive tour with Frank Sinatra

Your daily horoscope: June 18, 2026

Learn piano with AI feedback — a lifetime subscription to Skoove is $99.97

Police officer Stewart Copeland talks about his relationship with Sting

Trending Posts

Stand-up comic goes on extensive tour with Frank Sinatra

June 18, 2026

Police officer Stewart Copeland talks about his relationship with Sting

June 18, 2026

TOMORROW X TOGETHER, YEONJUN 2nd solo album release date announced

June 17, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.