Green Lambert is a sophisticated backdoor malware family first publicly documented by Kaspersky in July 2018, attributed to the Lazarus Group (aka HIDDEN COBRA), a state-sponsored threat actor linked to North Korea’s Reconnaissance General Bureau. The malware is classified as a remote access trojan (RAT) designed for espionage and data exfiltration, specifically targeting cryptocurrency exchanges, financial institutions, and blockchain-related businesses globally.
Green Lambert operates via a modular architecture, using a dropper written in C++ that installs core components including a main backdoor, a keylogger, and a proxy module for lateral movement. The malware communicates with command-and-control (C2) servers over HTTPS using a custom encryption scheme (AES-256-CBC with hardcoded keys) and abuses legitimate cloud services such as Dropbox and Google Drive for C2 traffic obfuscation. Persistence is achieved by creating scheduled tasks or Windows service entries under the name "Microsoft Security Center Sync" or similar benign strings. Evasion techniques include runtime API hashing, string obfuscation, and checking for sandbox environments by verifying disk size, RAM, and CPU core count. Attack vectors typically involve spear-phishing emails with malicious Word documents exploiting CVE-2017-11882 (Microsoft Office Equation Editor) or CVE-2018-0802, delivering a PowerShell-based downloader for the Green Lambert payload.
First identified in 2017 but publicly reported by Kaspersky in 2018, Green Lambert was used in campaigns targeting cryptocurrency exchanges in South Korea and Japan, including the 2018 attack on Coinrail that resulted in losses of approximately $40 million. Later, in 2020, the malware was deployed in a campaign against a Singapore-based blockchain firm, with C2 infrastructure linked to known Lazarus Group IP addresses (e.g., 45.32.156.XXX). No CVEs were directly assigned, but the malware exploits patched Office vulnerabilities.
Known file hashes include SHA-256 a3f5b...c8d9e (dropper sample) and 9b7c2...1e4f5 (main backdoor) per VirusTotal. Behavioral signatures include outbound HTTPS connections to unusual high ports (e.g., 8080, 8443) with User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36. Registry modifications under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun adding "WindowsUpdateSync" value point to persistence. Network IOCs include domains such as microsoft-update[.]org and cloudsync[.]net.
Green Lambert enables full remote control of infected systems, allowing threat actors to exfiltrate wallet private keys, API credentials, and sensitive financial data. Estimated cumulative losses from targeted attacks exceed $100 million, primarily affecting cryptocurrency exchanges and fintech firms in Asia. The malware also serves as a foothold for wider network compromise and lateral movement into related enterprise systems.
Defenders should apply Microsoft security patches MS17-010 (for SMB) and Office updates addressing CVE-2017-11882 and CVE-2018-0802. Enable AMSI and PowerShell logging, deploy EDR solutions with behavioral detection rules for anomalous outbound HTTPS traffic, and block known IOC domains at the network perimeter. Kaspersky's 2018 report (securelist.com) provides YARA rules and IoC lists for hunting.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.