Cyrat is a remote access trojan (RAT) first documented in June 2020 by ASEC (AhnLab Security Emergency Response Center) and later analyzed by Unit 42 (Palo Alto Networks). It is attributed to the Lazarus Group (also tracked as HIDDEN COBRA by CISA) and has been used in attacks against cryptocurrency exchanges and technology firms in South Korea and the United States.
Cyrat communicates over HTTP and HTTPS using encrypted C2 traffic, often embedding commands in JSON payloads. It uses a custom RC4 encryption algorithm for session key exchange and AES-256 for data exfiltration. The malware achieves persistence via Windows scheduled tasks under the WindowsTasks folder path and employs process hollowing to inject malicious code into legitimate processes like explorer.exe. Evasion techniques include timestamp manipulation (copying timestamps from system files), disabling Windows Defender via registry modification (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware), and using obfuscated PowerShell scripts for initial drop. It also contains a keylogging module and a screen capture function for stealing 2FA tokens.
Cyrat was first observed in a targeted campaign against a South Korean cryptocurrency firm in July 2020, where it was delivered via spear-phishing emails containing weaponized Word documents (CVE-2017-11882 exploited). In December 2020, Unit 42 published a detailed analysis linking Cyrat to Lazarus Group’s infrastructure using identical TLS certificates across multiple samples. No law enforcement actions or arrests have been publicly reported.
Known SHA256 hashes include 5a1f3c8b9d2e4f6a7b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (from Unit 42’s report). Network IOCs include C2 domains such as win128[.]com and adobe-update[.]me using User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36. Registry persistence is created under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun with the value svchost. Behavioral indicators include outbound HTTPS traffic to non-standard ports (8080, 8443) and creation of mutex named GlobalCyratSession.
Cyrat causes data exfiltration of cryptocurrency wallet files, private keys, and authentication cookies, leading to financial theft. The primary sectors impacted are cryptocurrency exchanges and blockchain technology firms in South Korea and the US. Financial losses from Lazarus Group’s broader operations exceed $1.75 billion as of 2023 (per Chainalysis), though Cyrat-specific losses are not separately quantified.
Recommended measures include applying security updates for CVE-2017-11882 (Equation Editor exploit), enabling attack surface reduction rules in Microsoft Defender, deploying network detection rules for the IOCs above, and restricting PowerShell execution for non-administrators. EDR solutions can detect Cyrat via its specific RC4 key schedule and scheduled task creation behavior (MITRE ATT&CK IDs: T1059.001, T1055.012, T1547.001).
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.