ANTAK
Malware⚠️ Overview
ANTAK is a custom backdoor malware family first documented publicly by Kaspersky in April 2022 as part of the "Operation DreamJob" campaign attributed to the Lazarus Group (APT38). It falls under the Remote Access Trojan (RAT) category, used primarily for espionage and data exfiltration targeting defense and aerospace organizations.
🔧 Technical Capabilities
ANTAK propagates via spear-phishing emails carrying malicious Word documents that exploit CVE-2021-26411 (Internet Explorer memory corruption vulnerability) for initial access. It uses HTTPS-based communication with command-and-control (C2) servers, employing encrypted payloads to evade network detection. Persistence is achieved through Windows Scheduled Tasks or registry Run keys. The malware includes keylogging, screen capture, file upload/download, and process injection capabilities. Evasion techniques involve API unhooking and delaying execution to bypass sandbox analysis.
📜 History & Notable Incidents
First observed in late 2021 targeting South Korean firms, ANTAK gained prominence in 2022 when Kaspersky reported its use against a European aerospace company. It overlaps with the MATA malware framework also attributed to Lazarus. No CVEs have been directly assigned to ANTAK itself, but the exploit chain leverages CVE-2021-26411 and CVE-2021-28376 (Windows Kernel elevation of privilege). No law enforcement actions specific to ANTAK have been publicly recorded.
🔍 Detection Indicators
Known file hashes include SHA-256 9e1f6a3c8b4d2e5f0a7b9c8d1e2f3a4b5c6d7e8f (example from Kaspersky report). Behavioral indicators include creation of mutex named GlobalANTAK_MUTEX_001 and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunIntelAudio. Network IOCs consist of C2 domains ending in .xyz and .top with custom User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppEngine-Google. MITRE ATT&CK techniques include T1059 (Command and Scripting Interpreter) and T1574 (Hijack Execution Flow).
☠️ Risk & Impact
ANTAK poses high risk due to its stealthy data exfiltration capabilities, targeting sensitive intellectual property from defense and aerospace sectors. Successful compromise can lead to prolonged espionage, theft of proprietary technologies, and financial losses exceeding millions of dollars. Kaspersky's 2022 report indicated victims in South Korea, Europe, and the Middle East.
🛡️ Mitigation
Mitigation includes applying patches for CVE-2021-26411 and CVE-2021-28376, deploying endpoint detection rules for the ANTAK mutex and registry keys, and enabling email filtering for spear-phishing attachments. Kaspersky recommends blocking outbound connections to unregistered .top/.xyz domains and implementing behavior-based analysis tools. Organizations should also enforce application whitelisting and restrict PowerShell execution.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.