Lazarus_Group__2020__Cisco_Talos_Intelligence_Group_-_Comprehensive_Threat_Intelligence_CRAT_wants_to_plunder_your_endpoints.pdf
ID: 63dc9344-165a-4d03-9150-598739b54998
STIX ID: report--63dc9344-165a-4d03-9150-598739b54998
Threat Score
78/100
Uploaded: 2026-08-15
Published Date: 2020-11-13
Last Modified Date: 2020-11-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos documents a modular remote access trojan called CRAT (v2) that can download and run plugins (keylogger, clipboard monitor, screen-capture and a ransomware plugin named Hansom). The report details infection vectors (malicious HWP exploiting CVE-2017-8291 for earlier variants), extensive obfuscation and anti-analysis techniques, persistence and loader behaviors, HTTP-based C2 protocols, full lists of IOCs (hashes, C2 URLs, mutex names, BTC addresses) and notes similarities to Lazarus activity.
