logo

Lazarus_Group__2020__Cisco_Talos_Intelligence_Group_-_Comprehensive_Threat_Intelligence_CRAT_wants_to_plunder_your_endpoints.pdf

ID: 63dc9344-165a-4d03-9150-598739b54998

STIX ID: report--63dc9344-165a-4d03-9150-598739b54998

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2020-11-13

Last Modified Date: 2020-11-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos documents a modular remote access trojan called CRAT (v2) that can download and run plugins (keylogger, clipboard monitor, screen-capture and a ransomware plugin named Hansom). The report details infection vectors (malicious HWP exploiting CVE-2017-8291 for earlier variants), extensive obfuscation and anti-analysis techniques, persistence and loader behaviors, HTTP-based C2 protocols, full lists of IOCs (hashes, C2 URLs, mutex names, BTC addresses) and notes similarities to Lazarus activity.