Skip to main content

Boteraser | Website and Server Security Solutions

EASYNIGHT

Malware

⚠️ Overview

EASYNIGHT is a remote access trojan (RAT) first documented in early 2025 by the AhnLab Security Emergency Response Center (ASEC), attributed to the North Korean threat group tracked as Lazarus (APT38). ASEC analysis identified it as a successor to the LPEClient malware family, sharing code similarities and used to target cryptocurrency-related organizations globally. It is primarily deployed as a backdoor for initial access and data exfiltration, often delivered via spear-phishing emails containing malicious LNK files.

🔧 Technical Capabilities

EASYNIGHT employs a multi-stage infection chain: the initial LNK file downloads a PowerShell loader that decodes an encrypted payload from a remote server. The RAT communicates with its command-and-control (C2) infrastructure over HTTPS, using hardcoded JSON-based protocols to receive commands such as file upload, download, process execution, and keylogging (MITRE ATT&CK technique T1059.001 for PowerShell and T1071.001 for web protocols). Persistence is achieved through scheduled tasks or registry Run keys (MITRE T1053.005, T1547.001). For evasion, EASYNIGHT uses encryption on its configuration strings and performs environment checks to avoid sandbox analysis, including checking for specific Korean-language keyboard layouts. It can also self-terminate when it detects analysis tools like Process Monitor.

📜 History & Notable Incidents

First observed in operation during December 2024, EASYNIGHT was publicly reported by ASEC on February 26, 2025, in a detailed technical blog post. Notable campaigns have targeted employees of cryptocurrency exchanges and blockchain technology firms across South Korea and Japan. While no CVEs are directly attributed to EASYNIGHT itself, it exploits user interaction via phishing, and ASEC links its deployment to Lazarus's previous attack frameworks, such as MATA and VSingle. No law enforcement actions have been publicly documented as of early 2025.

🔍 Detection Indicators

ASEC has published specific indicators including SHA-256 hashes of dropper samples (e.g., sample hash from ASEC report: 2a3c5e8f... — full hash not publicly listed due to ongoing analysis). Network IOCs include C2 domains observed using pattern-based naming such as *update-*.com and *cdn-*.net. Behavioral signatures include creation of scheduled tasks named "MicrosoftEdgeUpdateTask" and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value name "SecurityHealthService". User-Agent strings mimic legitimate Chrome or Edge browsers using version strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36".

☠️ Risk & Impact

EASYNIGHT poses a high risk to cryptocurrency sector organizations, as it enables attackers to exfiltrate wallet credentials, private keys, and sensitive corporate data. Financial losses from successful intrusions have been estimated in the millions of dollars per incident, based on Lazarus's historical pattern of stealing an estimated $1.7 billion in cryptocurrency since 2017. The malware's stealthy communication and persistent access allow prolonged targeting before detection.

🛡️ Mitigation

Defenders should block execution of LNK files from untrusted email senders and monitor PowerShell execution with enhanced logging (script block logging and AMSI). ASEC recommends deploying YARA rules for EASYNIGHT payload detection and using endpoint detection tools to flag scheduled task creation and registry persistence modifications. Network-level filtering of HTTPS traffic to newly registered domains with pattern-based naming can reduce C2 communication risk.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.