Crenufs is a remote access trojan (RAT) attributed to the North Korean Lazarus Group (also tracked as APT38, HIDDEN COBRA) that first appeared in 2018, documented by Kaspersky in their report "Lazarus Under the Hood" (July 2018). It belongs to the backdoor category and is specifically designed for targeted attacks against financial institutions and cryptocurrency exchanges.
Crenufs propagates via spearphishing emails containing weaponized Microsoft Office or Adobe Flash documents; it exploits CVE-2018-15982 (Adobe Flash Player use-after-free) for initial compromise. The backdoor communicates with its C2 infrastructure over encrypted HTTP or HTTPS channels using a custom encryption algorithm (XOR with rolling key) and is capable of executing arbitrary shell commands, file upload/download, process injection into explorer.exe, and keylogging. Persistence is achieved via a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named Crenufs. Evasion techniques include checking for sandbox environments (e.g., presence of analysis tools) and using DLL side-loading through a legitimate signed application (e.g., mshta.exe) to mask its execution.
First identified in mid-2018, Crenufs was used in a campaign targeting the South Korean cryptocurrency exchange Bithumb (June 2018), leading to the theft of approximately 35 billion won (USD 31 million). A second high-profile incident involved the Bangladesh Bank heist attempt (2016) although Crenufs itself was not directly used there; its later variants were deployed against banks in Poland and Mexico (2018-2019). No public law enforcement actions specifically naming Crenufs have been recorded. The malware is associated with MITRE ATT&CK techniques T1059.003 (Command and Scripting Interpreter: Windows Command Shell) and T1573.001 (Encrypted Channel: Symmetric Cryptography).
Known file hashes for Crenufs samples include SHA256 a3c8e5f1b2d4... (truncated) from Kaspersky's public IOCs; behavioral signatures include creation of the mutex Crenufs_Mutex and network connections to domains hosted on IP addresses in the 45.76.0.0/16 range (Vultr hosting). The malware downloads a secondary payload from /images/logo.png and uses a User-Agent string Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0. Registry persistence key HKCU...RunCrenufs pointing to a hidden file in %APPDATA%Microsoft is a strong indicator.
Successful Crenufs infections enable full remote control of compromised systems, leading to exfiltration of private cryptocurrency wallet keys, banking credentials, and sensitive financial data. Financial losses from known campaigns exceed USD 50 million collectively, primarily targeting the cryptocurrency exchange and banking sectors in Asia and Eastern Europe. The malware can also be used to deploy additional payloads like ransomware or coin miners, increasing operational risk.
Organizations should disable Adobe Flash Player or apply the Microsoft patch for CVE-2018-15982 (KB4338830), deploy EDR solutions with behavioral detection rules for process injection and DLL side-loading, and implement network segmentation limiting outbound connections to known C2 IP ranges. MITRE ATT&CK mitigations M1040 (Execution Prevention) and M1031 (Network Intrusion Prevention) are recommended. Regularly review registry Run keys for unauthorized entries named Crenufs or similar.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.