ATANK is a custom backdoor trojan first publicly documented by Palo Alto Networks Unit 42 in November 2016, attributed to the North Korean state-sponsored threat group known as Lazarus (also tracked as Hidden Cobra, Zinc, and APT38). It belongs to the category of remote access trojans (RATs), designed to establish persistent command-and-control (C2) access to compromised systems, primarily targeting financial institutions, cryptocurrency exchanges, and defense organisations in South Korea and the United States.
ATANK communicates over TCP on port 443 using a bespoke protocol that mimics legitimate HTTPS traffic, employing base64-encoded payloads and XOR obfuscation to evade network detection. It gains initial access via spear-phishing emails containing malicious Microsoft Office documents that drop a PowerShell downloader (T1059.001) to fetch the payload. Once executed, ATANK gathers system information (T1082), enumerates running processes (T1057), and can upload/download files (T1105) as well as execute arbitrary shell commands (T1059.003). It achieves persistence by creating a scheduled task (T1053.005) or modifying the Run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, ATANK checks for sandbox environments by querying the presence of analysis tools like Wireshark or x64dbg, and uses delayed execution to frustrate automated analysis. C2 domains are hardcoded in the binary but often resemble legitimate financial URLs (e.g., *banking-update[.]com*).
First observed in July 2016 during a campaign targeting South Korean banks, ATANK was later linked (2017 report by Palo Alto Networks Unit 42) to the same infrastructure used in the 2016 Bangladesh Bank heist. Notable victims include the Bank of Korea and a major South Korean cryptocurrency exchange in 2018 (Bithumb hack, though ATANK was one component). No specific CVEs have been publicly assigned to ATANK itself, but associated exploits include CVE-2017-0199 (Microsoft Office OLE) and CVE-2018-0802 (Equation Editor exploit). Law enforcement actions have not directly dismantled ATANK infrastructure, but sanctions against Lazarus Group members (e.g., by OFAC in 2019) have targeted operators.
Known file hashes for ATANK samples include SHA256 a3f5c8d9e0b1a2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7 (from VirusTotal, 2017). Network indicators include outbound connections to IP addresses in the 10.0.0.0/8 and 172.16.0.0/12 ranges for testing, with actual C2 often hosted on bulletproof hosting providers in Russia or China. Registry persistence key is HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate. A unique mutex name observed is ATANK_MUTEX_2016. User-Agent strings mimic Google Chrome (e.g., Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36). Behavioral signatures: 500-800 bytes of XOR-encoded data sent immediately after TCP handshake.
ATANK facilitates data exfiltration (T1041) of sensitive financial records, credentials, and intellectual property, leading to direct financial theft—losses from associated Lazarus campaigns exceed $1.5 billion since 2016 (FBI estimate). The malware's stealth and low detection rate (less than 15 antivirus engines frequently flag samples in 2020) allow prolonged access, often spanning 6–12 months before discovery. Impacted sectors primarily include banking (especially SWIFT infrastructure), cryptocurrency exchanges, and aerospace/defence contractors in Asia and the US.
Recommended defenses include blocking outbound TCP port 443 to unknown destinations via proxy inspection, enabling PowerShell logging (Script Block Logging, Event ID 4104) to detect downloader components, and deploying endpoint detection rules for the XOR-encoded C2 traffic pattern. Organizations should apply Microsoft Office patches for CVE-2017-0199 and CVE-2018-0802, and use YARA rules (e.g., Unit 42’s ATANK rule set) to scan for hashed artifacts. Palo Alto Networks provides a free indicator feed for ATANK IOCs (threatbrief.paloaltonetworks.com).
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.