EASYNIGHT is a remote access trojan (RAT) first documented in early 2025 by the AhnLab Security Emergency Response Center (ASEC), attributed to the North Korean threat group tracked as Lazarus (APT38). ASEC analysis identified it as a successor to the LPEClient malware family, sharing code similarities and used to target cryptocurrency-related organizations globally. It is primarily deployed as a backdoor for initial access and data exfiltration, often delivered via spear-phishing emails containing malicious LNK files.
EASYNIGHT employs a multi-stage infection chain: the initial LNK file downloads a PowerShell loader that decodes an encrypted payload from a remote server. The RAT communicates with its command-and-control (C2) infrastructure over HTTPS, using hardcoded JSON-based protocols to receive commands such as file upload, download, process execution, and keylogging (MITRE ATT&CK technique T1059.001 for PowerShell and T1071.001 for web protocols). Persistence is achieved through scheduled tasks or registry Run keys (MITRE T1053.005, T1547.001). For evasion, EASYNIGHT uses encryption on its configuration strings and performs environment checks to avoid sandbox analysis, including checking for specific Korean-language keyboard layouts. It can also self-terminate when it detects analysis tools like Process Monitor.
First observed in operation during December 2024, EASYNIGHT was publicly reported by ASEC on February 26, 2025, in a detailed technical blog post. Notable campaigns have targeted employees of cryptocurrency exchanges and blockchain technology firms across South Korea and Japan. While no CVEs are directly attributed to EASYNIGHT itself, it exploits user interaction via phishing, and ASEC links its deployment to Lazarus's previous attack frameworks, such as MATA and VSingle. No law enforcement actions have been publicly documented as of early 2025.
ASEC has published specific indicators including SHA-256 hashes of dropper samples (e.g., sample hash from ASEC report: 2a3c5e8f... — full hash not publicly listed due to ongoing analysis). Network IOCs include C2 domains observed using pattern-based naming such as *update-*.com and *cdn-*.net. Behavioral signatures include creation of scheduled tasks named "MicrosoftEdgeUpdateTask" and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value name "SecurityHealthService". User-Agent strings mimic legitimate Chrome or Edge browsers using version strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36".
EASYNIGHT poses a high risk to cryptocurrency sector organizations, as it enables attackers to exfiltrate wallet credentials, private keys, and sensitive corporate data. Financial losses from successful intrusions have been estimated in the millions of dollars per incident, based on Lazarus's historical pattern of stealing an estimated $1.7 billion in cryptocurrency since 2017. The malware's stealthy communication and persistent access allow prolonged targeting before detection.
Defenders should block execution of LNK files from untrusted email senders and monitor PowerShell execution with enhanced logging (script block logging and AMSI). ASEC recommends deploying YARA rules for EASYNIGHT payload detection and using endpoint detection tools to flag scheduled task creation and registry persistence modifications. Network-level filtering of HTTPS traffic to newly registered domains with pattern-based naming can reduce C2 communication risk.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.