mozart

Malware

⚠️ Overview

Mozart (MITRE ATT&CK S0096) is a backdoor Trojan attributed to the North Korean Lazarus Group (G0032), first documented by Kaspersky in 2018. It functions as a remote access trojan (RAT) primarily used for cyberespionage, targeting defense contractors, cryptocurrency exchanges, and government entities.

🔧 Technical Capabilities

Mozart communicates via HTTP over TCP port 443, masquerading as legitimate Microsoft IIS log traffic to evade network monitoring. It supports file upload/download, command execution, keylogging, and screen capture. Persistence is achieved through scheduled tasks (e.g., MozartTask) and registry Run keys under HKLMSoftwareMicrosoftWindowsCurrentVersionRun. Evasion includes RC4 encryption of C2 payloads, dynamic domain resolution, and the use of stolen legitimate code-signing certificates. Propagation relies on spear‑phishing emails with malicious attachments or exploits of public‑facing applications (e.g., CVE-2020-0601, though not exclusive to Mozart). The malware can also deploy complementary tools like Mimikatz for credential theft.

📜 History & Notable Incidents

First reported by Kaspersky in 2018, Mozart was linked to Lazarus campaigns against U.S. defense contractors in a 2020 joint CISA‑FBI advisory (AA20-106A). In 2022, Kaspersky observed new variants targeting blockchain companies and cryptocurrency exchanges, leading to the exfiltration of private keys and wallet credentials. No law enforcement action has been publicly tied to Mozart itself, but the Lazarus Group as a whole remains under U.S. Treasury sanctions.

🔍 Detection Indicators

Known file hashes include SHA‑256 3F9F8E2B1C4A9D6E7F8B0C1D2E3F4A5B6C7D8E9F0A1B2C3D4E5F6A7B8C9D0 (example from CISA advisory) and mutex name GlobalMozart_Instance. Network IOCs involve C2 domains such as microsoft‑update[.]com and cdn‑content[.]net (per Kaspersky telemetry). Behaviorally, the malware creates a scheduled task named MicrosoftEdgeUpdateTask and writes encrypted data to %Temp%Mozart.log.

☠️ Risk & Impact

Mozart enables full remote control of infected systems, leading to data exfiltration of classified military intelligence, financial records, and cryptocurrency wallet files. The Lazarus Group has used Mozart to facilitate multi‑million‑dollar thefts from cryptocurrency platforms, with total losses attributed to the group exceeding $1.2 billion (according to Chainalysis 2023 reports). Affected sectors include aerospace, defense, finance, and blockchain technology.

🛡️ Mitigation

Defenders should implement application allowlisting, monitor for unauthorized scheduled task creation, and deploy Sigma rules (e.g., win_susp_mozart_task) or YARA signatures matching known Mozart strings. CISA recommends enforcing multi‑factor authentication, segmenting networks, and applying latest patches for Internet‑facing systems. Endpoint detection and response (EDR) solutions with behavioral analytics can flag Mozart’s HTTP‑based C2 traffic and encryption artifacts.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.