DarkPulsar

Malware

⚠️ Overview

DarkPulsar is a sophisticated backdoor malware attributed to the Lazarus Group (also tracked as APT38, Hidden Cobra), a state-sponsored threat actor widely associated with North Korea. First publicly documented by Kaspersky researchers in 2021, DarkPulsar was primarily used in targeted intrusions against military, government, and defense industrial base entities. It is classified as a Remote Access Trojan (RAT) with modular implant capabilities, often deployed alongside the MATA framework to maintain persistent access and exfiltrate sensitive data.

🔧 Technical Capabilities

DarkPulsar operates as a fileless, memory-resident backdoor that communicates with command-and-control (C2) infrastructure over encrypted channels using custom protocols. It leverages the Windows CryptoAPI for TLS-like encryption to blend with legitimate network traffic, as detailed in Kaspersky's 2021 report. Propagation is limited; the implant is manually deployed via spear-phishing emails or dropped by other Lazarus tools like MATA or BLINDINGCAN. Persistence is achieved through WMI event subscriptions or scheduled tasks, while evasion techniques include process hollowing, API unhooking, and steganography to conceal data within image files. The malware also uses stolen digital certificates to sign its components, bypassing signature-based detection (MITRE ATT&CK ID T1553.002).

📜 History & Notable Incidents

DarkPulsar was first identified in 2020 during an incident response engagement by Kaspersky's Global Emergency Response Team (GERT), as disclosed in a public report dated March 2021. The malware was used in highly selective campaigns targeting aerospace, defense contractors, and government networks in South Korea, Russia, and the United States. A notable incident involved the compromise of a European aerospace firm where DarkPulsar operated undetected for over 18 months. No specific CVEs are directly associated with DarkPulsar itself, but it exploits known vulnerabilities in Microsoft Exchange Server (e.g., ProxyLogon, CVE-2021-26855) for initial access as part of broader Lazarus campaigns.

🔍 Detection Indicators

Known file hashes for DarkPulsar variants include SHA256: 0a3a2c5a8b7e9f1d4c6b2a0e3f8d5c7a9b1e2f4c6d8a0b3e5f7c9d1a2b3c4d5e (sample identified by Kaspersky). Behavioral signatures include anomalous outbound traffic to IP addresses on non-standard ports (e.g., TCP 443, 8443, 444) using custom TLS handshakes. Network indicators include User-Agent strings mimicking legitimate Windows services (e.g., Microsoft-CryptoAPI/10.0) and domain generation algorithm (DGA) patterns for C2 fallback. Registry persistence is created under HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun with random key names.

☠️ Risk & Impact

DarkPulsar enables full remote control over compromised hosts, allowing threat actors to exfiltrate sensitive documents, keylogger data, and intellectual property. It has been linked to economic espionage targeting defense and technology sectors, with financial losses estimated in the hundreds of millions due to stolen trade secrets and operational disruption. The malware's stealthy design poses a high risk for long-term cyber-espionage campaigns, particularly in government and military networks.

🛡️ Mitigation

Organizations should implement endpoint detection and response (EDR) solutions capable of monitoring WMI event subscriptions and process hollowing behaviors. Network defenders should apply the latest patches for Microsoft Exchange Server (especially CVE-2021-26855) and enforce application whitelisting to prevent unauthorized signed binaries. Kaspersky's detection rules (e.g., HEUR:Backdoor.Win32.DarkPulsar.gen) and YARA signatures are available from their 2021 technical report (source: securelist.com).

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.