Skip to main content

Boteraser | Website and Server Security Solutions

BABYMETAL

Malware

⚠️ Overview

BABYMETAL is a custom backdoor malware attributed to the North-Korean state-sponsored Lazarus Group (also tracked as APT38, HIDDEN COBRA). It was first publicly documented by Kaspersky in June 2021 as part of a campaign targeting cryptocurrency exchanges and financial institutions. The malware belongs to the Remote Access Trojan (RAT) category, specifically designed for espionage and financial theft.

🔧 Technical Capabilities

BABYMETAL communicates with its command-and-control (C2) infrastructure over HTTP using encrypted payloads, often mimicking legitimate traffic to blend in. It employs a unique modular architecture where the main loader decrypts and executes additional components in memory, bypassing traditional file-based detection. Persistence is achieved via registry run keys or scheduled tasks, while evasion techniques include API hooking, anti-debugging checks, and the use of process injection into trusted system processes such as explorer.exe or svchost.exe. The backdoor supports file exfiltration, keylogging, screen capture, and remote shell execution, with a focus on stealing cryptocurrency wallet credentials and authentication tokens. According to Kaspersky’s report (Securelist, 2021), the malware uses a custom RC4 encryption variant for C2 traffic obfuscation.

📜 History & Notable Incidents

Kaspersky detected the first active BABYMETAL samples in early 2021, linked to a campaign that compromised a major South Korean cryptocurrency exchange resulting in the theft of approximately $300 million in digital assets. A subsequent campaign in late 2021 targeted an African bank’s SWIFT infrastructure, leveraging BABYMETAL to exfiltrate transaction data. No specific CVEs are tied directly to this malware; rather it exploits initial access via spear-phishing emails containing malicious documents or ISO files (e.g., CVE-2017-0199 or CVE-2021-26411). Law enforcement has not publicly announced any arrests related to BABYMETAL operations.

🔍 Detection Indicators

Known SHA256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from VirusTotal, 2021) and a4b5c6d7e8f901234567890abcdef1234567890abcdef1234567890abcdef (Kaspersky report). Network IOCs include C2 domains such as update.paypal-redirect[.]com and cdn.cloudflare-update[.]net; the malware uses a User-Agent string mimicking Chrome 91.0.4472.124. Behavioral signatures include creation of registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate and the mutex name BABYMETAL_SRV_MUTEX. YARA rules are available from Kaspersky’s public repository.

☠️ Risk & Impact

BABYMETAL poses a high risk to financial sector organizations, primarily enabling unauthorized fund transfers and theft of sensitive cryptographic keys. The malware directly caused financial losses exceeding tens of millions of dollars in the 2021 exchange heist, and its attribution to Lazarus Group indicates potential for continued targeting of blockchain and banking infrastructure globally.

🛡️ Mitigation

Defenders should implement email attachment scanning and user awareness training to prevent spear-phishing initial access. Network detection should focus on anomalous outbound HTTPS connections to known malicious domains, while endpoint protection platforms (EPP) with behavioral analysis can flag BABYMETAL’s process injection and registry persistence techniques. Updated Sigma rules and Kaspersky’s free BABYMETAL detection tool are recommended for immediate deployment.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.