Thursday, February 20, 2025
HomeCryptocurrency hackLazarus Hacking Group Delivering RATANKBA Malware & Remote Hacking Tool Via MS...

Lazarus Hacking Group Delivering RATANKBA Malware & Remote Hacking Tool Via MS Office Documents

Published on

SIEM as a Service

Follow Us on Google News

Lazarus Hacking group Spreading Weaponized RATANKBA Malware and sophisticated hacking tools via Microsoft office documents that could mainly affect the cryptocurrencies.

The Lazarus Hacking group has had multiple operations over the years around 2014-2016, most of which involve either disruption, sabotage, financial theft or espionage.

RATANKBA is used by this cyberespionage Campaign for targeting financial institutions and this malware has been active since 2016.

Cybercriminals mainly used this sophisticated RATANKBA malware to delivering the Powerful payloads and Remote hacking tools to compromise banking systems.

Lazarus Hacking group uses a number of backend servers to keep the stolen data that has been collected from mainly India and surrounding Asian countries.

According to the report, the majority of the observed victims were not using
enterprise versions of Microsoft software. Less than 5% of the victims were
Microsoft Windows Enterprise users, which means that currently, RATANKBA
mostly affects smaller organizations or individual users, not larger
organizations.

Lazarus intelligence also capable of recording the Victim IP Address who is mainly working in the Web development based IT Firms in Asian based countries.

Also Read: Most Advanced APT Malware “CrossRAT” Globally Targeting Individuals & Exfiltrate Text Messages, Photos, Call Records

How Does Lazarus Hacking Group Attack the Victims

This Hacking Group Delivering this RATANKBA Malware via Malicious Word Documents, CHM files and script downloader which contains an information that related to software development and digital currencies.

Once the Victims click the malicious file that drives by the MS office document, it drops the backdoor and it makes a communication with command & control server.

RATANKBA Malware

Initial conversation with communication has been initiated using HTTP GET or POST to the server.

Backdoor is responsible for upload the information that was collected from the infected machine.

According to Trend Micro Report, It uses 4 commands that make to assign the
Follwing task for the backdoor.  
  • Killkill: Stops the backdoor’s activities
  • interval: Changes the interval in which the backdoor retrieves jobs; the
    default interval is set at 120 seconds
  • cmd: Executes shell commands
  • exe: Reflectively injects a DLL downloaded from a specific URL

Lazarus’s Remote Controller Tool – RATANKBA Malware

Lazarus Hacking Group used Remote controller tool of RATANKBA malware which helps to send jobs to any compromised endpoint using a user interface.

An attacker can able to manipulate the compromised victim’s host using this remote controller tool and also it retrieve a task from its command & control server and collecting the information by executing the task.

In this case, both Remote controller tool and backdoor commonly communicate with its command & control server instead of communicating directly to the attacker.

Both Backdoor and Remote controller is kept communicating with C&C server to complete the bending task.

"While we do not have any knowledge of who the actual Lazarus attackers are,
the data collected from the backend systems gives us some insights into the
internet usage patterns of systems likely owned by Lazarus group members.
Trend Micro Said."
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Check Point Software to Open First Asia-Pacific R&D Centre in Bengaluru, India

Check Point Software Technologies Ltd. has announced plans to establish its inaugural Asia-Pacific Research...

PoC Exploit Released for Ivanti EPM Vulnerabilities

A recent investigation into Ivanti Endpoint Manager (EPM) has uncovered four critical vulnerabilities that...

Ransomware Trends 2025 – What’s new

As of February 2025, ransomware remains a formidable cyber threat, evolving in complexity and...

Hackers Delivering Malware Bundled with Fake Job Interview Challenges

ESET researchers have uncovered a series of malicious activities orchestrated by a North Korea-aligned...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Hackers Delivering Malware Bundled with Fake Job Interview Challenges

ESET researchers have uncovered a series of malicious activities orchestrated by a North Korea-aligned...

New Bookworm Malware Using SLL Sideloading Technique To Windows

Cybersecurity researchers from Palo Alto Networks' Unit 42 disclosed the resurgence of the Bookworm...

Fake Chrome Update Delivers DriverEasy Malware by Abusing Dropbox

A recent investigation has uncovered a malicious application, DriverEasy, masquerading as a legitimate Google...