logo

The GDPR Playbook: Discover, Plan, and Act on the Upcoming EU Data Protection Regulation

ID: 2ef50f4e-135e-44e6-a551-42035e5c6431

STIX ID: report--2ef50f4e-135e-44e6-a551-42035e5c6431

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2017-12-19

Last Modified Date: 2017-12-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint analysis attributes an extensive, financially motivated Lazarus Group campaign to a new PowerShell downloader family (PowerRatankba) and related tools (PowerSpritz, Gh0st RAT, RatankbaPOS). The campaigns use diverse delivery methods—spearphishing, LNK/CHM/JS downloaders, macro-laden Office documents, and backdoored PyInstaller installers mimicking cryptocurrency wallets—to steal cryptocurrency credentials and scrape POS track data (South Korea), with extensive IOCs and C2 details provided.