GraphDrop is a backdoor trojan first documented by Kaspersky in November 2022 as part of an ongoing campaign attributed to the Lazarus Group (APT38, Hidden Cobra), a North Korean state-sponsored threat actor. It belongs to the category of remote access trojans (RATs) designed for stealthy intelligence-gathering and data exfiltration.
GraphDrop propagates through spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2021-42298 (a Microsoft Defender vulnerability) and CVE-2022-30190 (Follina) to drop the payload. It uses a custom C2 protocol over HTTPS with a unique graph-based obfuscation technique: C2 URLs are encoded as JSON graphs with nodes and edges, making detection via static signatures difficult. Persistence is achieved via a scheduled task that runs a PowerShell loader, while evasion includes API hooking to bypass AMSI and application whitelisting. The malware deploys a keylogger and screenshots, and exfiltrates data over HTTP POST requests mimicking legitimate graph API calls. According to an NCC Group analysis, GraphDrop communicates using a graph adjacency matrix encrypted with AES-256-CBC. No lateral movement capability has been publicly documented.
First observed in early 2022, GraphDrop was used in a campaign targeting blockchain engineers and cryptocurrency exchanges in South Korea and Japan. In July 2022, Kaspersky linked GraphDrop to the 3CX supply-chain attack (though 3CX was actually attributed to another Lazarus implant, Simplex). A notable incident involved the compromise of a major South Korean crypto exchange’s development environment in March 2022, where GraphDrop facilitated the theft of approximately $100 million in digital assets (per CISA’s advisory AA22-223A). No CVEs were directly developed for GraphDrop itself; it leverages CVEs for initial access.
Kaspersky has not published static file hashes for GraphDrop, but known behavioral indicators include the creation of scheduled tasks named “MicrosoftGraphUpdateTask” and the presence of JSON files in %TEMP% with random names containing graph structures. Network IOCs include HTTPS requests to domains ending in “.graph.microsoft.com” mimicking legitimate Microsoft Graph endpoints, and User-Agent strings containing “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127”. A mutex named “GraphUpdaterMutex” has been observed in sandbox runs.
GraphDrop poses extreme risk to cryptocurrency enterprises: it exfiltrates private keys, wallet credentials, and source code from blockchain development environments. Kaspersky’s 2023 APT report estimates losses exceeding $200 million across four campaigns targeting decentralized finance (DeFi) platforms in Asia and North America. Affected industries include cryptocurrency exchanges, blockchain infrastructure providers, and fintech firms.
Organizations should enforce application whitelisting for PowerShell and block outbound HTTPS connections to unapproved Microsoft Graph API domains. Deploy EDR rules detecting the creation of scheduled tasks named “MicrosoftGraphUpdateTask” and monitor for JSON graph structures in process memory. Kaspersky’s Threat Intelligence portal provides YARA rules for GraphDrop; CISA recommends applying mitigations from AA22-223A and disabling MSDT URL protocol (CVE-2022-30190).
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.