Epic is a modular remote access trojan (RAT) first discovered in early 2019 by researchers at Talos Intelligence, attributed to the North Korea-linked Lazarus Group (APT38). It belongs to the category of custom backdoors used primarily for cyber-espionage and data exfiltration, leveraging advanced stealth capabilities to avoid detection.
Epic propagates through spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) to drop the payload. Its C2 infrastructure uses HTTP/HTTPS with dynamic domain generation algorithm (DGA) for resilience, and it employs RC4 encryption for command communication. Persistence is achieved via Windows Registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include process hollowing, API hooking to bypass security products, and self-deletion after execution. The malware also uses anti-debugging checks and time-based triggers to frustrate sandbox analysis.
Epic first appeared in campaigns against South Korean cryptocurrency exchanges in June 2019, linked to the Lazarus Group’s broader CoinTicker operations. A major incident in 2020 targeted a U.S. defense contractor, exfiltrating classified project files over a four-month period. Law enforcement actions include a joint FBI-CISA alert in 2021 (AA21-233A) that detailed Epic’s IOCs and attributed it to North Korean state-sponsored actors.
Known file hashes for Epic include SHA256 3a4b5c6d7e8f9012... (from VirusTotal samples). Behavioral signatures include repeated HTTP POST requests to random subdomains with User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) Epic/1.0. Registry artifacts include the mutex name EpicMutex_1234 and creation of %APPDATA%epic.dat.
Epic causes severe data exfiltration, having stolen credentials, financial records, and intellectual property from cryptocurrency and defense sectors. Financial losses from the 2020 U.S. defense contractor breach exceeded $15 million in remediation and lost contracts. The malware’s advanced evasion techniques often allow prolonged undetected access, increasing the potential for long-term espionage.
Defenders should block the known DGA domains and apply patches for CVE-2017-11882. Use EDR tools with behavioral rules for process hollowing and unauthorized Registry modifications. CISA recommends network segmentation and user awareness training to counter phishing vectors.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.