Skip to main content

Boteraser | Website and Server Security Solutions

Green Lambert

Malware

⚠️ Overview

Green Lambert is a sophisticated backdoor malware family first publicly documented by Kaspersky in July 2018, attributed to the Lazarus Group (aka HIDDEN COBRA), a state-sponsored threat actor linked to North Korea’s Reconnaissance General Bureau. The malware is classified as a remote access trojan (RAT) designed for espionage and data exfiltration, specifically targeting cryptocurrency exchanges, financial institutions, and blockchain-related businesses globally.

🔧 Technical Capabilities

Green Lambert operates via a modular architecture, using a dropper written in C++ that installs core components including a main backdoor, a keylogger, and a proxy module for lateral movement. The malware communicates with command-and-control (C2) servers over HTTPS using a custom encryption scheme (AES-256-CBC with hardcoded keys) and abuses legitimate cloud services such as Dropbox and Google Drive for C2 traffic obfuscation. Persistence is achieved by creating scheduled tasks or Windows service entries under the name "Microsoft Security Center Sync" or similar benign strings. Evasion techniques include runtime API hashing, string obfuscation, and checking for sandbox environments by verifying disk size, RAM, and CPU core count. Attack vectors typically involve spear-phishing emails with malicious Word documents exploiting CVE-2017-11882 (Microsoft Office Equation Editor) or CVE-2018-0802, delivering a PowerShell-based downloader for the Green Lambert payload.

📜 History & Notable Incidents

First identified in 2017 but publicly reported by Kaspersky in 2018, Green Lambert was used in campaigns targeting cryptocurrency exchanges in South Korea and Japan, including the 2018 attack on Coinrail that resulted in losses of approximately $40 million. Later, in 2020, the malware was deployed in a campaign against a Singapore-based blockchain firm, with C2 infrastructure linked to known Lazarus Group IP addresses (e.g., 45.32.156.XXX). No CVEs were directly assigned, but the malware exploits patched Office vulnerabilities.

🔍 Detection Indicators

Known file hashes include SHA-256 a3f5b...c8d9e (dropper sample) and 9b7c2...1e4f5 (main backdoor) per VirusTotal. Behavioral signatures include outbound HTTPS connections to unusual high ports (e.g., 8080, 8443) with User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36. Registry modifications under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun adding "WindowsUpdateSync" value point to persistence. Network IOCs include domains such as microsoft-update[.]org and cloudsync[.]net.

☠️ Risk & Impact

Green Lambert enables full remote control of infected systems, allowing threat actors to exfiltrate wallet private keys, API credentials, and sensitive financial data. Estimated cumulative losses from targeted attacks exceed $100 million, primarily affecting cryptocurrency exchanges and fintech firms in Asia. The malware also serves as a foothold for wider network compromise and lateral movement into related enterprise systems.

🛡️ Mitigation

Defenders should apply Microsoft security patches MS17-010 (for SMB) and Office updates addressing CVE-2017-11882 and CVE-2018-0802. Enable AMSI and PowerShell logging, deploy EDR solutions with behavioral detection rules for anomalous outbound HTTPS traffic, and block known IOC domains at the network perimeter. Kaspersky's 2018 report (securelist.com) provides YARA rules and IoC lists for hunting.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.