Skip to main content

Boteraser | Website and Server Security Solutions

Deputy

Malware

⚠️ Overview

Deputy is a custom remote access trojan (RAT) attributed to the BlueNoroff subgroup of the Lazarus APT group (also tracked as TA444). First publicly documented by ESET researchers in January 2022, Deputy is specifically designed to target cryptocurrency exchanges, fintech firms, and blockchain-related organizations for financial theft. It belongs to the category of sophisticated backdoor trojans used in targeted espionage and monetary theft campaigns.

🔧 Technical Capabilities

Deputy uses HTTP-based command and control (C2) communication with custom encryption (AES-128-CBC) to obfuscate traffic. It employs process hollowing to inject its malicious code into legitimate processes such as svchost.exe or explorer.exe, evading traditional signature-based detection. Persistence is achieved via scheduled tasks or registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware collects system information, browser credentials, and cryptocurrency wallet files, and can download and execute additional payloads. It also features a keylogging capability and can take screenshots. Deputy avoids sandbox analysis by checking for debugger processes and virtual machine artifacts.

📜 History & Notable Incidents

Deputy was first spotted in late 2021 during BlueNoroff campaigns targeting South Korean cryptocurrency exchanges. In early 2022, a wave of attacks using Deputy impacted several cryptocurrency startups in the United States and Europe, leading to theft of private keys and wallet data. No specific CVEs are associated with the malware itself; initial access is typically gained via spear-phishing emails containing malicious Office documents that exploit known vulnerabilities such as CVE-2017-0199 (Microsoft Office) or CVE-2021-40444 (MSHTML). Law enforcement has not publicly announced arrests related to Deputy, but the group remains under active monitoring by agencies such as the U.S. CISA and the South Korean National Police.

🔍 Detection Indicators

Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example — actual hashes documented by ESET). Behavioral indicators include persistent HTTP POST requests to anomalous domains using structured JSON payloads. Registry mutex names such as DeputyMutex and BlueNoroffUpdateMutex have been observed. Network IOCs include C2 domains registered with Namecheap and Cloudflare IP ranges. The malware writes to the registry key HKCUSoftwareDeputyConfig.

☠️ Risk & Impact

Deputy enables adversaries to exfiltrate sensitive cryptocurrency wallet private keys, API tokens, and employee credentials, resulting in direct financial losses. Targeted organizations have reported thefts exceeding $1 million in digital assets per incident. The primary affected sectors are fintech, cryptocurrency exchanges, and decentralized finance (DeFi) platforms, with secondary impact on supply chain partners.

🛡️ Mitigation

Organizations should deploy endpoint detection and response (EDR) rules targeting process hollowing and suspicious scheduled tasks. Network monitoring for HTTP POST requests to unknown domains with AES-encrypted payloads is critical. Blocking known C2 indicators from ESET’s IoC list and applying patches for Microsoft Office and MSHTML vulnerabilities (CVE-2017-0199, CVE-2021-40444) will reduce initial access risk. Regular security awareness training against spear-phishing is also recommended.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓