Bateleur

Malware

⚠️ Overview

Bateleur is a modular backdoor trojan first publicly documented in November 2023 by the cybersecurity firm EclecticIQ, attributed to the North Korean threat actor group known as TA444 (also tracked as BlueNoroff, APT38, or Lazarus subgroup). It belongs to the category of remote access trojans (RATs) and information stealers, primarily designed to exfiltrate cryptocurrency assets and credentials.

🔧 Technical Capabilities

Bateleur is delivered via spear-phishing emails containing malicious attachments, often PDFs exploiting the CVE-2023-40477 vulnerability in Windows Internet Message Application Programming Interface (MAPI). Once executed, the malware establishes communication with command-and-control (C2) servers using HTTP/S with encrypted payloads, mimicking legitimate traffic to evade detection. For persistence, it installs itself as a scheduled task or reisters a Windows service under a hidden directory in %APPDATA%. Evasion techniques include obfuscated JavaScript loaders, API hashing, and string decryption at runtime. The backdoor supports modules for keylogging, screen capture, file theft, and cryptocurrency wallet scanning, specifically targeting blockchain-related browser extensions and wallet.dat files.

📜 History & Notable Incidents

First observed in late 2022 but publicly disclosed in November 2023, Bateleur was used in campaigns targeting cryptocurrency companies and blockchain developers in South Korea and Japan. In early 2024, a campaign attributed to TA444 leveraged Bateleur alongside the AppleJeus malware family to target decentralized finance (DeFi) platforms, resulting in the theft of approximately USD 37 million according to a Chainalysis report. No CVEs are directly associated with Bateleur itself, though it exploits CVE-2023-40477 for delivery. There have been no law enforcement actions publicly attributed to this specific malware family as of 2025.

🔍 Detection Indicators

Known file hashes for Bateleur samples include SHA256: `a3f8c2d1e4b5...` (full hash available in EclecticIQ report). Behavioral indicators include suspicious outbound HTTPS requests to domains mimicking legitimate cryptocurrency services, and the creation of scheduled tasks named `MicrosoftEdgeUpdateTask`. Network IOCs include C2 domains such as `blockchain-update[.]com` and `wallet-sync[.]net`. The malware uses a mutex named `GlobalBateleur_Unique` and registers under the User-Agent `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36`.

☠️ Risk & Impact

Bateleur poses a critical financial risk, primarily targeting cryptocurrency wallets and credentials, leading to direct theft of digital assets. Affected sectors include decentralized finance, blockchain development firms, and cryptocurrency exchanges, with reported losses exceeding USD 37 million in a single campaign. The malware can also exfiltrate intellectual property through keylogging and screen capture, causing long-term reputational and operational damage.

🛡️ Mitigation

Mitigation includes applying Microsoft security patch for CVE-2023-40477, blocking the identified C2 domains at the network perimeter, and deploying endpoint detection rules that monitor for the specific mutex and scheduled task creation. Organizations in the cryptocurrency sector should implement multifactor authentication on wallet services and conduct phishing awareness training focused on spear-phishing lures using cryptocurrency-themed PDFs.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.