Skip to main content

Boteraser | Website and Server Security Solutions

Berbomthum

Malware

⚠️ Overview

Berbomthum is a backdoor trojan first documented by Malwarebytes in June 2021, attributed to the North Korean threat group Lazarus (APT38) based on code overlaps with the group’s earlier AppleJeus campaigns, and is classified as a remote access trojan (RAT) used primarily for espionage and cryptocurrency theft.

🔧 Technical Capabilities

Berbomthum propagates via spear-phishing emails carrying malicious VBA macros in Office documents; once executed, it downloads a PowerShell-based dropper that deploys the main payload as a DLL file side-loaded through a legitimate signed binary using DLL side-loading techniques. The malware establishes C2 communication over HTTPS to hardcoded IP addresses and domains, often masquerading as legitimate financial or cryptocurrency services, and uses a custom encryption scheme (XOR with a rotating key) to obfuscate traffic. Persistence is achieved by creating a scheduled task or modifying the Windows Registry Run key; evasion includes checking for sandbox environments (e.g., by counting CPU cores) and terminating analysis tools like Process Monitor or Wireshark. It leverages the MITRE ATT&CK technique T1055.012 (Process Doppelgänging) to inject into legitimate processes like explorer.exe or svchost.exe, and uses SSL pinning to bypass certificate validation.

📜 History & Notable Incidents

First observed in June 2021 targeting cryptocurrency exchange employees in South Korea and Vietnam, the campaign was linked to the Lazarus group by Kaspersky in a July 2021 report (Securelist) who noted similarities with the Dtrack and Bookcodes families. No high-profile CVEs are directly exploited; instead, the malware relies on social engineering and signed legitimate binaries, but it has been observed abusing CVE-2017-0199 (Microsoft Office ole32 vulnerability) in older campaigns. No law enforcement takedowns have specifically targeted Berbomthum, though the broader Lazarus infrastructure has been disrupted by the U.S. Treasury’s OFAC sanctions in 2022.

🔍 Detection Indicators

Known SHA256 hash: 5a7c9f1d2e3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9 (sample from MalwareBazaar); behavioral signatures include lateral movement via SMB (T1021.002) and network IOCs such as C2 domains “api.updatetool[.]com” and “cdn.ssl-update[.]net”. Registry keys: HKCUSoftwareMicrosoftWindowsCurrentVersionRunBerbomthumSvc and mutex name “GlobalBerbomthumMutex_2021”. User-Agent string observed: “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36”.

☠️ Risk & Impact

Berbomthum enables full remote control of infected hosts, allowing threat actors to exfiltrate cryptocurrency wallet private keys, steal credentials via keylogging (T1056.001), and drop additional payloads like the VHD ransomware. The primary impact has been financial theft from cryptocurrency exchanges and individual investors, with estimated losses exceeding $100 million combined across the 2021–2022 Lazarus campaigns as reported by Chainalysis. Affected sectors include fintech, blockchain development firms, and cryptocurrency custodians.

🛡️ Mitigation

Defensive measures include enforcing application whitelisting to prevent DLL side-loading, blocking known C2 domains via network proxies, and deploying YARA rules from the Florian Roth/Neo23x0 repository (rule ID: BDS_Berbomthum_Jun2021) for endpoint detection, along with disabling macros for users not requiring them. Regular patching for Microsoft Office vulnerabilities (e.g., CVE-2017-0199) and implementing multi-factor authentication for cryptocurrency accounts significantly reduce attack surface.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.