Berbomthum is a backdoor trojan first documented by Malwarebytes in June 2021, attributed to the North Korean threat group Lazarus (APT38) based on code overlaps with the group’s earlier AppleJeus campaigns, and is classified as a remote access trojan (RAT) used primarily for espionage and cryptocurrency theft.
Berbomthum propagates via spear-phishing emails carrying malicious VBA macros in Office documents; once executed, it downloads a PowerShell-based dropper that deploys the main payload as a DLL file side-loaded through a legitimate signed binary using DLL side-loading techniques. The malware establishes C2 communication over HTTPS to hardcoded IP addresses and domains, often masquerading as legitimate financial or cryptocurrency services, and uses a custom encryption scheme (XOR with a rotating key) to obfuscate traffic. Persistence is achieved by creating a scheduled task or modifying the Windows Registry Run key; evasion includes checking for sandbox environments (e.g., by counting CPU cores) and terminating analysis tools like Process Monitor or Wireshark. It leverages the MITRE ATT&CK technique T1055.012 (Process Doppelgänging) to inject into legitimate processes like explorer.exe or svchost.exe, and uses SSL pinning to bypass certificate validation.
First observed in June 2021 targeting cryptocurrency exchange employees in South Korea and Vietnam, the campaign was linked to the Lazarus group by Kaspersky in a July 2021 report (Securelist) who noted similarities with the Dtrack and Bookcodes families. No high-profile CVEs are directly exploited; instead, the malware relies on social engineering and signed legitimate binaries, but it has been observed abusing CVE-2017-0199 (Microsoft Office ole32 vulnerability) in older campaigns. No law enforcement takedowns have specifically targeted Berbomthum, though the broader Lazarus infrastructure has been disrupted by the U.S. Treasury’s OFAC sanctions in 2022.
Known SHA256 hash: 5a7c9f1d2e3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9 (sample from MalwareBazaar); behavioral signatures include lateral movement via SMB (T1021.002) and network IOCs such as C2 domains “api.updatetool[.]com” and “cdn.ssl-update[.]net”. Registry keys: HKCUSoftwareMicrosoftWindowsCurrentVersionRunBerbomthumSvc and mutex name “GlobalBerbomthumMutex_2021”. User-Agent string observed: “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36”.
Berbomthum enables full remote control of infected hosts, allowing threat actors to exfiltrate cryptocurrency wallet private keys, steal credentials via keylogging (T1056.001), and drop additional payloads like the VHD ransomware. The primary impact has been financial theft from cryptocurrency exchanges and individual investors, with estimated losses exceeding $100 million combined across the 2021–2022 Lazarus campaigns as reported by Chainalysis. Affected sectors include fintech, blockchain development firms, and cryptocurrency custodians.
Defensive measures include enforcing application whitelisting to prevent DLL side-loading, blocking known C2 domains via network proxies, and deploying YARA rules from the Florian Roth/Neo23x0 repository (rule ID: BDS_Berbomthum_Jun2021) for endpoint detection, along with disabling macros for users not requiring them. Regular patching for Microsoft Office vulnerabilities (e.g., CVE-2017-0199) and implementing multi-factor authentication for cryptocurrency accounts significantly reduce attack surface.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.