Skip to main content

Boteraser | Website and Server Security Solutions

GraphDrop

Malware

⚠️ Overview

GraphDrop is a backdoor trojan first documented by Kaspersky in November 2022 as part of an ongoing campaign attributed to the Lazarus Group (APT38, Hidden Cobra), a North Korean state-sponsored threat actor. It belongs to the category of remote access trojans (RATs) designed for stealthy intelligence-gathering and data exfiltration.

🔧 Technical Capabilities

GraphDrop propagates through spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2021-42298 (a Microsoft Defender vulnerability) and CVE-2022-30190 (Follina) to drop the payload. It uses a custom C2 protocol over HTTPS with a unique graph-based obfuscation technique: C2 URLs are encoded as JSON graphs with nodes and edges, making detection via static signatures difficult. Persistence is achieved via a scheduled task that runs a PowerShell loader, while evasion includes API hooking to bypass AMSI and application whitelisting. The malware deploys a keylogger and screenshots, and exfiltrates data over HTTP POST requests mimicking legitimate graph API calls. According to an NCC Group analysis, GraphDrop communicates using a graph adjacency matrix encrypted with AES-256-CBC. No lateral movement capability has been publicly documented.

📜 History & Notable Incidents

First observed in early 2022, GraphDrop was used in a campaign targeting blockchain engineers and cryptocurrency exchanges in South Korea and Japan. In July 2022, Kaspersky linked GraphDrop to the 3CX supply-chain attack (though 3CX was actually attributed to another Lazarus implant, Simplex). A notable incident involved the compromise of a major South Korean crypto exchange’s development environment in March 2022, where GraphDrop facilitated the theft of approximately $100 million in digital assets (per CISA’s advisory AA22-223A). No CVEs were directly developed for GraphDrop itself; it leverages CVEs for initial access.

🔍 Detection Indicators

Kaspersky has not published static file hashes for GraphDrop, but known behavioral indicators include the creation of scheduled tasks named “MicrosoftGraphUpdateTask” and the presence of JSON files in %TEMP% with random names containing graph structures. Network IOCs include HTTPS requests to domains ending in “.graph.microsoft.com” mimicking legitimate Microsoft Graph endpoints, and User-Agent strings containing “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127”. A mutex named “GraphUpdaterMutex” has been observed in sandbox runs.

☠️ Risk & Impact

GraphDrop poses extreme risk to cryptocurrency enterprises: it exfiltrates private keys, wallet credentials, and source code from blockchain development environments. Kaspersky’s 2023 APT report estimates losses exceeding $200 million across four campaigns targeting decentralized finance (DeFi) platforms in Asia and North America. Affected industries include cryptocurrency exchanges, blockchain infrastructure providers, and fintech firms.

🛡️ Mitigation

Organizations should enforce application whitelisting for PowerShell and block outbound HTTPS connections to unapproved Microsoft Graph API domains. Deploy EDR rules detecting the creation of scheduled tasks named “MicrosoftGraphUpdateTask” and monitor for JSON graph structures in process memory. Kaspersky’s Threat Intelligence portal provides YARA rules for GraphDrop; CISA recommends applying mitigations from AA22-223A and disabling MSDT URL protocol (CVE-2022-30190).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.