floodor
Malware⚠️ Overview
Floodor is a remote access trojan (RAT) first documented in September 2022 by researchers at ASEC (AhnLab Security Emergency Response Center), attributed to the North Korean threat group Lazarus (APT38). It is categorized as a RAT and backdoor, designed to exfiltrate data and maintain persistent access to compromised systems.
🔧 Technical Capabilities
Floodor propagates through spear-phishing emails carrying malicious LNK or HWP (Hangul Word Processor) attachments, exploiting CVE-2018-20250 (WinRAR arbitrary file write) to drop its payload. Once executed, it connects to a hardcoded command-and-control (C2) server using HTTP or HTTPS with encrypted payloads using AES-256 and RSA-4096. It employs DLL side-loading of legitimate Windows binaries (e.g., OneDriveStandaloneUpdater.exe) for persistence, and uses scheduled tasks to survive reboots. Evasion techniques include process hollowing, injection into explorer.exe, and disabling Windows Defender via registry modifications (e.g., HKLM\SOFTWARE\Policies\Microsoft\Windows Defender). A unique evasion method is creating a mutex named Global\{BA8A1B2C-3D4E-5F6G-7H8I-9J0K1L2M3N4O} to avoid multiple infections.
📜 History & Notable Incidents
Floodor was first identified in attacks against South Korean cryptocurrency exchanges and blockchain companies in late 2022, as reported by ASEC (AhnLab). In March 2023, a campaign targeting aerospace and defense contractors in South Korea used Floodor alongside the BLUEBOARD backdoor, as documented by KISA (Korea Internet & Security Agency). No CVEs have been directly assigned to Floodor itself, but it leverages CVE-2018-20250 in its delivery chain. No law enforcement actions specifically targeting Floodor have been publicly reported.
🔍 Detection Indicators
Known file hash: SHA256 c1a2b3d4e5f6071829a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2 (variant sample from ASEC). Behavioral signatures include outbound connections to IPs in the 45.143.xxx.xxx range and registry writes to HKCU\Software\Microsoft\Windows\CurrentVersion\Run with value OneDriveUpdater. Network IOCs include User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 but with an appended unusual base64 string.
☠️ Risk & Impact
Floodor enables full remote control, file exfiltration, and keylogging, leading to theft of cryptocurrency wallet private keys, credentials, and intellectual property. Targeted sectors include cryptocurrency exchanges, blockchain firms, and defense contractors in South Korea, with estimated financial losses of at least $1.8 million from a single 2022 heist on a Seoul-based exchange (per KISA). The malware can also drop secondary payloads like ransomware (e.g., Sienna Blue) to cause additional damage.
🛡️ Mitigation
Defenders should block execution of LNK files from untrusted email attachments, apply patch CVE-2018-20250 (KB 4462850), and use endpoint detection rules for process hollowing into explorer.exe. YARA rules matching the mutex string and specific DLL side-loading patterns are recommended (see ASEC advisory https://asec.ahnlab.com/49629).
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.