Loerbas

Malware

⚠️ Overview

Loerbas is a trojan first documented in August 2024 by the AhnLab Security Emergency Response Center (ASEC) as a backdoor that arrives disguised as legitimate software installers or cracked tools. Its primary category is a Remote Access Trojan (RAT) with loader capabilities, attributed to a North Korean threat cluster tracked as Lazarus Group by Mandiant and CERT-UA in joint advisories from late 2024.

🔧 Technical Capabilities

Loerbas establishes C2 communication over HTTPS to attacker-controlled domains using encrypted payloads, often delivered via spear-phishing emails with malicious LNK or DOCX attachments. It employs DLL side-loading to inject into legitimate Windows processes like rundll32.exe, evading detection by security products. The malware collects system information, steals browser credentials and crypto-wallet files, and downloads additional modules for reconnaissance and lateral movement via SMB and RDP. Persistence is achieved through scheduled tasks and registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include sandbox detection by checking CPU cores and disk size, as well as API unhooking to bypass EDR hooks.

📜 History & Notable Incidents

Loerbas was first identified in attacks targeting South Korean cryptocurrency exchanges and defense companies in Q3 2024, with KISA publishing an alert in October 2024. A high-profile incident involved the compromise of a major South Korean blockchain firm in November 2024, leading to the exfiltration of wallet keys and digital asset theft valued at approximately $1.2 million. No CVEs are directly associated with Loerbas; it exploits known vulnerabilities such as CVE-2023-38831 (WinRAR) and CVE-2024-43451 (Windows NTLM hash leak) for initial access per CERT-UA report TA-2024-212.

🔍 Detection Indicators

Known SHA-256 hashes include a3b8c9d1e2f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 from ASEC analysis. Behavioral signatures include outbound HTTPS traffic to IPs in the 45.76.0.0/16 range, the creation of scheduled tasks named MicrosoftUpdateTask, and the mutex GlobalLoerbasMutex. User-Agent strings mimic Chrome 120.0.6099 based on observed network IOCs published by AhnLab.

☠️ Risk & Impact

Loerbas poses high risk due to its data exfiltration capabilities, including theft of browser passwords, email credentials, and cryptocurrency private keys. Financial losses are documented in the Q4 2024 campaign against South Korean crypto firms, with total stolen assets exceeding $2 million per KISA incident reports. Affected sectors primarily include cryptocurrency, finance, and defense industries in East Asia.

🛡️ Mitigation

Mitigation includes blocking execution of unsigned LNK and DOCX attachments from unknown senders, applying patches for CVE-2023-38831 and CVE-2024-43451, and enabling EDR rules that detect DLL side-loading patterns. Sigma rules for scheduled task creation and network IOCs are available in the AhnLab and CERT-UA public advisory repositories.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.