logo

Three Lazarus RATs coming for your cheese

ID: 9a4b180c-96ac-5adb-b567-ff4d5127abef

STIX ID: report--9a4b180c-96ac-5adb-b567-ff4d5127abef

Feed Name: Fox-IT blog

Threat Score
88/100

Date Published: 2025-09-01

Date Updated: 2026-04-27

...
...

This Fox-IT/NCC Group report documents a Lazarus subgroup targeting cryptocurrency and DeFi organizations via Telegram social engineering, suspected Chrome zero-day exploitation, and staged deployment of multiple RATs (PondRAT, ThemeForestRAT) followed by a more advanced RemotePE loader; it analyzes persistence (phantom DLL loading with PerfhLoader), C2 protocols, command functionality, ties to POOLRAT/ROMEOGOLF-era tooling, and provides extensive IOCs, YARA rules, and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.