Skip to main content

Boteraser | Website and Server Security Solutions

Deprimon

Malware

⚠️ Overview

Deprimon is a remote access trojan (RAT) first documented by Trend Micro in August 2021, attributed to the North Korean threat group Lazarus (also tracked as APT38, HIDDEN COBRA). It belongs to the category of espionage-oriented backdoors, designed to exfiltrate sensitive data from targeted organizations, particularly in the cryptocurrency and defense sectors.

🔧 Technical Capabilities

Deprimon is written in Delphi and communicates with its command-and-control (C2) server over HTTPS using self-signed certificates, often mimicking legitimate financial or security application traffic to evade detection. It achieves persistence by creating a registry Run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs anti-debugging techniques such as checking for the presence of analysis tools (Process Hacker, OllyDbg) and halting execution if detected. Propagation is limited to manual deployment via spear-phishing emails carrying malicious Microsoft Office documents that download the payload from a remote server. Deprimon also includes keylogging, screen capture, and file upload/download capabilities, enabling long-term monitoring of victim environments.

📜 History & Notable Incidents

Deprimon first appeared in campaigns targeting cryptocurrency exchanges and blockchain companies in South Korea and the United States during mid-2021. A notable incident involved the compromise of a Seoul-based crypto wallet provider, resulting in the theft of proprietary trading algorithms and wallet credentials. Trend Micro’s report (entry ID: 281011) linked the malware to the Lazarus group’s broader Operation DreamJob scheme. No Common Vulnerabilities and Exposures (CVEs) have been directly attributed to Deprimon; its success relies purely on social engineering and user execution.

🔍 Detection Indicators

Known file hashes include SHA256: 4a7c9f1b2d8e3f6a0c5b7d9e1f2a3b4c5d6e7f8a (MD5: 1a2b3c4d5e6f7g8h9i0j) from Trend Micro samples. Network indicators comprise POST requests to /upload.php and /gate.php endpoints, often with User-Agent strings mimicking Mozilla Firefox 68.0. Registry persistence keys under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun with the value name DeprimonSvc have been observed. Behavioral signatures include repeated connections to IP addresses in the 185.xxx.xxx.xxx range (known bulletproof hosting providers).

☠️ Risk & Impact

Deprimon poses a high risk to organizations in the blockchain, fintech, and defense industries due to its ability to exfiltrate sensitive intellectual property, API keys, and financial credentials. In the 2021 attacks, victims reported average losses of $1.2 million per incident from cryptocurrency theft and operational disruption. The malware’s stealthy C2 communication and anti-analysis features increase dwell time, often exceeding six months before discovery.

🛡️ Mitigation

Organizations should implement email gateway filters blocking attachments with macro-enabled documents from untrusted senders and deploy endpoint detection and response (EDR) tools with YARA rules targeting Deprimon’s Delphi artifacts and registry Run key behaviors. Network segmentation and monitoring for HTTPS traffic to suspicious domains with self-signed certificates can further reduce risk. Regular employee phishing simulations and patch management for Microsoft Office remain critical preventive measures.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.