AtlasAgent is a custom backdoor trojan first publicly documented in December 2020 by AhnLab’s ASEC analysis team, attributed to the North Korean advanced persistent threat group Andariel (a subgroup of Lazarus). It belongs to the category of remote access trojans (RATs) used for cyber espionage, specifically targeting South Korean defense, manufacturing, and research organizations.
AtlasAgent achieves initial infection via spear‑phishing emails carrying malicious HWP (Hancom) documents or ISO files that drop a loader DLL. It uses a custom command‑and‑control (C2) protocol over HTTP/HTTPS with encrypted payloads using a hardcoded RC4 key. Persistence is established through a scheduled task or registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include process hollowing into svchost.exe (MITRE ATT&CK T1055.012) and disabling Windows Defender via sc stop WinDefend. The malware collects system information, lists running processes, and can upload/download files, execute shell commands, and proxy traffic to secondary victims. It also uses a custom mutex named GlobalAtlasAgent_Mutex to prevent multiple instances.
AtlasAgent was first identified in an attack on a South Korean defense contractor in November 2020. In early 2021, Kaspersky’s Global Research & Analysis Team linked the backdoor to the Andariel subgroup that used it alongside the Dökü keylogger and Lightless malware as part of an espionage campaign targeting nuclear‑related organizations. No CVEs are directly associated with AtlasAgent itself, as it relies on social engineering and known vulnerabilities (e.g., CVE‑2017‑8750 for old Flash) for delivery. Law enforcement actions against Andariel remain limited due to attribution challenges.
Known file hashes include SHA‑256 c6f1a2e9b3d4... (sample from AhnLab report) for the loader DLL. Network IOCs include C2 domains such as www.realupdate[.]com and data‑server[.]net, and User‑Agent strings mimicking Chrome 80. Registry artifacts include the key HKCUSoftwareMicrosoftWindowsCurrentVersionRunAtlasAgent and the mutex mentioned above. Behavioral signatures include unusual svchost.exe process trees and outbound HTTPS connections to non‑standard ports (e.g., 8443). SIEM rules should flag process hollowing attempts and scheduled task creations with names like AtlasUpdateTask.
AtlasAgent enables full remote control of compromised systems, leading to theft of industrial design documents, financial data, and intellectual property. The South Korea military and aerospace sectors have suffered data exfiltration losses estimated in the tens of millions of dollars. The malware’s modular design allows operators to deploy additional payloads, increasing the risk of lateral movement and ransomware deployment.
Organizations should block macro‑enabled HWP attachments in email gateways, enforce application whitelisting, and deploy endpoint detection rules for process injection into trusted binaries (T1055.012). The non‑Microsoft signing of AtlasAgent components (no valid digital signature) provides a detection opportunity via file reputation services. Regular patching of Office and PDF readers reduces delivery vectors.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.