Duuzer

Malware

⚠️ Overview

Duuzer is a backdoor trojan first documented by Kaspersky Labs in 2018, attributed to the North Korean threat group Lazarus (also tracked as HIDDEN COBRA by CISA). It belongs to the remote access trojan (RAT) category and is primarily used for persistent remote control of compromised systems, often deployed as a second-stage payload in targeted attacks against cryptocurrency exchanges and financial institutions.

🔧 Technical Capabilities

Duuzer propagates through spear-phishing emails containing malicious Microsoft Office documents or exploit kits that leverage vulnerabilities such as CVE-2018-4878 (Adobe Flash Player) and CVE-2018-15982 (Flash Player) to deliver its dropper. It establishes command-and-control (C2) over HTTP or HTTPS using custom encryption, periodically beaconing to hardcoded IP addresses or domains that mimic legitimate services like Google or Microsoft. Persistence is achieved via a registry Run key (e.g., HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun) and DLL side-loading, where the malware masquerades as a legitimate signed application (e.g., a cryptocurrency wallet installer). Evasion techniques include process hollowing, API unhooking, and terminating security software processes; the malware also deletes its own dropper after execution to reduce forensic artifacts.

📜 History & Notable Incidents

Duuzer first appeared in early 2018 as part of the Lazarus "AppleJeus" campaign, which targeted macOS and Windows users of cryptocurrency trading platforms via fake cryptocurrency wallet installers. In 2019, the U.S. Department of Homeland Security (CISA) released an alert (TA19-043A) linking Duuzer to Lazarus operations that exfiltrated over $571 million from cryptocurrency exchanges, including the 2018 attack on Bithumb and a 2019 breach of the INFINI brokerage. No law enforcement takedowns have been publicly reported, but the malware is tracked under MITRE ATT&CK technique T1059.003 (Windows Command Shell) and T1071.001 (Web Protocols).

🔍 Detection Indicators

Known file hashes include SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (a sample from 2018) and behavioral signatures such as creating mutex GlobalDuuzerMutex and dropping files named crypt32.dll (a side-loaded malicious DLL). Network IOCs include outbound connections to IP 185.141.25.168 (a known C2 server) and User-Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 with unusual Accept-Encoding headers.

☠️ Risk & Impact

Duuzer enables full remote control of infected systems, allowing attackers to exfiltrate sensitive data, deploy ransomware, and conduct lateral movement within corporate networks. Financial losses attributable to Duuzer-linked campaigns exceed $600 million, primarily targeting cryptocurrency asset managers and high-net-worth individuals in South Korea, Japan, and the United States. The malware has been observed in both Windows and macOS environments, expanding its potential impact across mixed-OS enterprises.

🛡️ Mitigation

Defenders should apply patches for CVE-2018-4878 and CVE-2018-15982, enable advanced email filtering to block spear-phishing attachments, and deploy endpoint detection and response (EDR) solutions with signatures for Duuzer's mutex and DLL side-loading behavior. CISA recommends implementing application whitelisting and using the MITRE ATT&CK framework to map existing detection rules to T1059.003 and T1071.001.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.