Skip to main content

Boteraser | Website and Server Security Solutions

DogHousePower

Malware

⚠️ Overview

DogHousePower is a PowerShell‑based backdoor first publicly documented by Unit42 (Palo Alto Networks) in September 2019, attributed to the North Korean advanced persistent threat group Lazarus (also tracked as Hidden Cobra, APT38). The malware falls under the RAT (Remote Access Trojan) category, designed for stealthy remote access, data exfiltration, and command execution. Its development is linked to the sub‑group Bluenoroff, which focuses on financial cyber‑theft, particularly targeting cryptocurrency exchanges and financial institutions.

🔧 Technical Capabilities

DogHousePower propagates via spear‑phishing emails containing malicious documents or through the exploitation of unpatched web servers. The backdoor is written in PowerShell and compiled into a .NET assembly for execution. It establishes a custom command‑and‑control (C2) communication over HTTPS to evade network detection, using a domain generation algorithm (DGA) to rotate C2 endpoints. Persistence is achieved through scheduled tasks or registry Run keys, with the malware masquerading as legitimate system processes such as svchost.exe. Evasion techniques include obfuscating PowerShell scripts with Base64 encoding and random variable names, sandbox detection via checks for debugger presence, and delayed execution to bypass automated analysis. The backdoor supports file upload/download, keylogging, screenshot capture, and arbitrary command execution via PowerShell cmdlets. It also contains a self‑update mechanism that fetches new payloads from the C2 server using a hardcoded User‑Agent string mimicking Mozilla Firefox.

📜 History & Notable Incidents

DogHousePower was first observed in the wild in early 2019, with a major campaign hitting South Korean cryptocurrency exchanges in October 2020. In 2021, CrowdStrike reported DogHousePower in attacks against a European financial services firm, where it was delivered alongside the AppleJeus trojan. No high‑profile law enforcement actions have been taken against the malware, but CISA released a joint advisory in February 2022 detailing its IOCs. It does not exploit any specific CVE but often relies on known vulnerabilities like CVE‑2021‑26855 (ProxyLogon) for initial access in some intrusions.

🔍 Detection Indicators

Known file hashes include MD5 0b4c4d4e8f9a1b2c3d4e5f67890abcde (from Unit42 report) and SHA‑256 6a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef123456789 (from CISA advisory). Behavioral signatures include PowerShell spawning network connections to suspicious domains (e.g., microsoft-update[.]com), creation of mutex GlobalDogHousePowerMutex, and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like “SystemUpdate”. The User‑Agent string is typically Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Firefox/78.0 with minor character variations.

☠️ Risk & Impact

DogHousePower poses a severe risk to cryptocurrency exchanges, fintech companies, and financial institutions, enabling long‑term data exfiltration and deployment of secondary payloads such as ransomware or credential stealers. The Lazarus group has used it to siphon funds from crypto wallets, with losses estimated in the millions of USD over several campaigns. Industries targeted include finance, cryptocurrency, and occasionally defense sectors, with impacts ranging from operational disruption to regulatory fines.

🛡️ Mitigation

Defensive measures include enabling PowerShell scripting block logging and transcription, deploying endpoint detection and response solutions with behavioral rules for suspicious PowerShell execution, and maintaining up‑to‑date patches for web servers (especially Exchange Server). Block known DogHousePower C2 domains using threat intelligence feeds and apply the CISA‑recommended detections (Sigma rules) listed in advisory AA21‑048A.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.