CALMTHORN

Malware
description

⚠️ Overview

CALMTHORN is a remote access trojan (RAT) attributed to the North Korean threat group Lazarus (also tracked as HIDDEN COBRA). First publicly documented by South Korea’s National Intelligence Service in coordination with KISA in 2022, CALMTHORN is a custom-built malware developed specifically for espionage operations targeting South Korean defense contractors, government agencies, and academic institutions. It belongs to the RAT category with modular capabilities for remote command execution and data exfiltration.

🔧 Technical Capabilities

CALMTHORN uses a modular architecture where the main loader decrypts and executes plug‑ins retrieved from a command‑and‑control (C2) server. Propagation occurs via spear‑phishing emails carrying malicious LNK files or VBA macros; once executed, it establishes persistence through scheduled tasks (MITRE ATT&CK T1053.005) and registry Run keys (MITRE ATT&CK T1547.001). C2 communication uses a custom‑encrypted protocol over HTTPS to blend with legitimate traffic, with the victim’s system beaconing to a remote IP or domain. Evasion techniques include API hooking to disable Windows Defender and obfuscation of strings via AES‑128 encryption. The malware can enumerate files, capture keystrokes, take screenshots, and exfiltrate data over FTP or via the C2 channel using a custom‑formatted HTTP POST request (MITRE ATT&CK T1005).

📜 History & Notable Incidents

CALMTHORN was first identified in mid‑2022 during a campaign targeting South Korea’s defense supply chain. A notable incident involved the compromise of a major defense contractor’s internal network; the attackers used CALMTHORN to steal blueprints and technical documents related to shipbuilding and missile systems. No specific CVEs have been publicly linked to CALMTHORN’s deployment, but the initial vector exploited unpatched Microsoft Office vulnerabilities (CVE‑2021‑40444-like older payloads) and social engineering. As of early 2025, no law enforcement actions have been reported against the Lazarus subgroup operating CALMTHORN.

🔍 Detection Indicators

Known file hashes for CALMTHORN loaders are not widely published, but behavioral indicators include creation of scheduled tasks named “update_task” or “onenote_loader” and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value name “mssecsvc”. Network IOCs include HTTPS beacons to domains ending in .top or .xyz with User‑Agent strings like “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36”. Mutex names such as “Globalcalt0” have been observed in malware samples.

☠️ Risk & Impact

CALMTHORN poses a high risk to organizations in the defense, aerospace, and government sectors. The malware enables persistent remote access, leading to exfiltration of sensitive design documents, classified military plans, and intellectual property. Financial impact is indirect but severe, as stolen blueprints can cripple competitive advantage and national security; South Korea’s Defense Acquisition Program Administration reported losses exceeding $10 million from data leaks tied to Lazarus RAT campaigns in 2023–2024.

🛡️ Mitigation

Organizations should enforce application allow‑listing and block execution of LNK files from untrusted email attachments. Deploy endpoint detection and response (EDR) rules to monitor for suspicious scheduled tasks and registry Run key additions. Network defenders can filter HTTPS traffic to known bad domains using threat intelligence feeds from KISA or Kaspersky’s Lazarus‑specific IoC lists.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.