216.73.216.6

Three Lazarus RATs coming for your cheese

· Published 03/09/2025 17:31 · Modified 03/09/2025 20:38

Export JSON

Essential information

Published
03/09/2025 17:31
Modified
03/09/2025 20:38
Tags
2025-09-02 2025-09-03 cryptocurrency financial pondrat poolrat rat remotepe social engineering themeforestrat zero-day
Related entities
1 intrusion sets (apt), 24 techniques (mitre), 1 others

Description

This report analyzes three remote access trojans (RATs) used by a Lazarus subgroup targeting and organizations: , , and . It details an incident response case from 2024 involving and possible exploitation. is described as a simple initial access tool, while is a more capable memory-only used in conjunction. appears to be an advanced deployed in later attack stages. The analysis reveals connections between these tools and previously known Lazarus malware like . The report highlights the actor's persistence, sophistication, and continued threat to targets.

External references