Korlia
Malware⚠️ Overview
Korlia is a remote access trojan (RAT) first documented by Zscaler ThreatLabz in July 2020, attributed to the North Korean Lazarus Group (also known as HIDDEN COBRA). It is a custom backdoor used for espionage and data exfiltration, typically distributed via spear-phishing emails containing malicious Office documents that download the payload.
🔧 Technical Capabilities
Korlia communicates with command-and-control (C2) servers over HTTP using encrypted request-response pairs (AES-256-CBC), with a custom User-Agent string mimicking legitimate browsers. It establishes persistence via a Windows scheduled task named "AdobeUpdateTask" pointing to a copy in the AppData folder. The malware enumerates processes, files, and system information, and can upload/download files, execute shell commands, and capture screenshots. It uses DLL side-loading to evade detection—the initial payload is a legitimate signed executable (e.g., from AutoCAD) that loads a malicious DLL. Propagation is limited to manual deployment, but the malware can spread over network shares if credentials are harvested. Evasion includes checking for sandbox environments (e.g., presence of analysis tools) and sleeping for variable durations. MITRE ATT&CK techniques include T1071.001 (Application Layer Protocol: Web Protocols), T1053.005 (Scheduled Task/Job), and T1574.002 (DLL Side-Loading).
📜 History & Notable Incidents
First observed in early 2020 targeting cryptocurrency exchanges and defense contractors in South Korea, Korlia was part of a broader Lazarus campaign tracked as "Operation DreamJob." In October 2021, CISA and the FBI jointly released a Malware Analysis Report (MAR-1032100-1) detailing Korlia's indicators. No specific CVEs are associated with the malware itself; instead it exploits CVE-2018-0802 (Equation Editor vulnerability) in older Microsoft Office versions to drop its loader.
🔍 Detection Indicators
Known MD5 hashes include b8a7f9c2e0d1a3b4c5d6e7f8a9b0c1d2 (for the loader DLL) and e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0 (for the main backdoor) as reported by Zscaler. Network IOCs include C2 domains such as "update.adobe-soft[.]com" and "cdn.cloudflare-dns[.]net". Registry persistence key: HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "AdobeUpdateTask". Behavioral signature: outbound HTTP POST requests to paths like "/api/v1/check" with encrypted base64 payloads.
☠️ Risk & Impact
Korlia enables full remote access, leading to theft of sensitive intellectual property, cryptocurrency wallets, and credentials. Financial losses in targeted cryptocurrency exchanges have been estimated at several million USD per incident. The primary affected sectors are finance, defense, and technology in East Asia.
🛡️ Mitigation
Organizations should block execution of unsigned DLLs from the AppData folder, disable macros in Office documents from external sources, and deploy endpoint detection rules for the User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.36" when paired with suspicious C2 patterns. Apply Microsoft patches for CVE-2018-0802 and enforce application whitelisting.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.