• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE

Admin by Admin
September 2, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Sep 02, 2025Ravie LakshmananMalware / Risk Intelligence

The North Korea-linked risk actor referred to as the Lazarus Group has been attributed to a social engineering marketing campaign that distributes three totally different items of cross-platform malware referred to as PondRAT, ThemeForestRAT, and RemotePE.

The assault, noticed by NCC Group’s Fox-IT in 2024, focused a corporation within the decentralized finance (DeFi) sector, in the end resulting in the compromise of an worker’s system.

“From there, the actor carried out discovery from contained in the community utilizing totally different RATs together with different instruments, for instance, to reap credentials or proxy connections,” Yun Zheng Hu and Mick Koomen mentioned. “Afterwards, the actor moved to a stealthier RAT, seemingly signifying a subsequent stage within the assault.”

The assault chain begins with the risk actor impersonating an current worker of a buying and selling firm on Telegram and utilizing faux web sites masquerading as Calendly and Picktime to schedule a gathering with the sufferer.

Audit and Beyond

Though the precise preliminary entry vector is presently not identified, the foothold is leveraged to deploy a loader referred to as PerfhLoader, which then drops PondRAT, a identified malware assessed to be a stripped-down variant of POOLRAT (aka SIMPLESEA). The cybersecurity firm mentioned there’s some proof to recommend {that a} then-zero-day exploit within the Chrome browser was used within the assault.

Additionally delivered together with PondRAT are numerous different instruments, together with a screenshotter, keylogger, Chrome credential and cookie stealer, Mimikatz, FRPC, and proxy applications like MidProxy and Proxy Mini.

“PondRAT is an easy RAT that enables an operator to learn and write information, begin processes, and run shellcode,” Fox-IT mentioned, including it dates again to not less than 2021. “The actor used PondRAT together with ThemeForestRAT for roughly three months, to afterwards clear up and set up the extra subtle RAT referred to as RemotePE.”

The PondRAT malware is designed to speak over HTTP(S) with a hard-coded command-and-control (C2) server to obtain additional directions, with ThemeForestRAT launched instantly in reminiscence both through PondRAT or a devoted loader.

ThemeForestRAT, like PondRAT, displays for brand spanking new Distant Desktop (RDP) classes and contacts a C2 server over HTTP(S) to retrieve as many as twenty instructions to enumerate information/directories, carry out file operations, execute instructions, take a look at TCP connection, timestomp file primarily based on one other file on disk, get course of itemizing, obtain a information, inject shellcode, spawn processes, and hibernate for a selected period of time.

CIS Build Kits

Fox-IT mentioned ThemeForestRAT shares similarities with a malware codenamed RomeoGolf that was put to make use of by the Lazarus Group within the November 2014 harmful wiper assault towards Sony Footage Leisure (SPE). It was documented by Novetta as a part of a collaborative effort referred to as Operation Blockbuster.

RemotePE, alternatively, is retrieved from a C2 server by RemotePELoader, which, in flip, is loaded by DPAPILoader. Written in C++, RemotePE is a extra superior RAT that is seemingly reserved for high-value targets.

“PondRAT is a primitive RAT that gives little flexibility, nonetheless, as an preliminary payload it achieves its objective,” Fox-IT mentioned. “For extra complicated duties, the actor makes use of ThemeForestRAT, which has extra performance and stays beneath the radar as it’s loaded into reminiscence solely.”

Tags: ArsenalexpandsGroupLazarusMalwarePondRATRemotePEThemeForestRAT
Admin

Admin

Next Post
Uncover the High 10 Various Websites for Omegle

Uncover the High 10 Various Websites for Omegle

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025
Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025
Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Prime 10 Ransomware Targets by Business

Prime 10 Ransomware Targets by Business

February 11, 2026
Examine: Platforms that rank the most recent LLMs may be unreliable | MIT Information

Examine: Platforms that rank the most recent LLMs may be unreliable | MIT Information

February 11, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved