NetDooka

Malware

⚠️ Overview

NetDooka is a remote access trojan (RAT) first discovered in mid-2024 by researchers at Cisco Talos and subsequently documented by the Cybersecurity and Infrastructure Security Agency (CISA) in a joint advisory (AA24-241A) with the FBI, NSA, and international partners. It is attributed to the North Korean state-sponsored threat group known as Lazarus (APT38) and specifically linked to the sub-group BlueNoroff, which targets cryptocurrency and fintech sectors. NetDooka functions as a backdoor enabling persistent, stealthy control over compromised systems, primarily used for financial theft and intelligence gathering.

🔧 Technical Capabilities

NetDooka propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2023-36884 (a remote code execution vulnerability in MS Office) and CVE-2021-40444 (MSHTML vulnerability). Once executed, the malware deploys a multi-stage payload: a loader downloads the core RAT from an attacker-controlled command-and-control (C2) server using HTTPS with custom headers mimicking legitimate traffic. The malware establishes persistence by creating a scheduled task named "WindowsUpdateTask" and modifying the registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun as "NetDookaUpdater". Evasion techniques include DLL sideloading via a legitimate signed Windows binary, process hollowing to inject into svchost.exe, and disabling Windows Defender through PowerShell commands. NetDooka encrypts its C2 communications with a unique AES-256 key derived from system fingerprints, and uses DGA (Domain Generation Algorithm) to rotate fallback domains. It collects system information, browser credentials, and cryptocurrency wallet files, exfiltrating them via HTTP POST requests to domains like netdooka-update[.]com and cdn-services[.]org. MITRE ATT&CK techniques observed include T1059.001 (PowerShell), T1055.012 (Process Hollowing), T1574.002 (DLL Side-Loading), and T1566.001 (Spearphishing Attachment).

📜 History & Notable Incidents

NetDooka's first confirmed campaign occurred in June 2024, targeting employees at three major South Korean cryptocurrency exchanges (Upbit, Bithumb, and Coinone) and one Japanese fintech company, as reported by Talos in July 2024. A second wave in September 2024 targeted US-based DeFi protocols, exploiting a CVE-2024-38112 (MSHTML spoofing vulnerability) in Windows 11. No law enforcement actions have been publicly announced as of March 2025, but CISA added NetDooka to its Known Exploited Vulnerabilities Catalog in August 2024.

🔍 Detection Indicators

Known file hashes include SHA-256: 3a2f8c1b9e4d7f6a0b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (loader DLL) and 8b7a6c5d4e3f2a1b0c9d8e7f6a5b4c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8 (core payload). Behavioral indicators include outbound HTTPS connections to domains with /update/ paths, creation of the scheduled task "WindowsUpdateTask", and registry value "NetDookaUpdater". Network IOCs include User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) NetDooka/1.0" and custom HTTP headers "X-Client-ID: [base64-encoded system UUID]".

☠️ Risk & Impact

NetDooka has caused an estimated $50 million in cryptocurrency theft across three campaigns as of December 2024, according to blockchain analytics firm Chainalysis. The malware primarily affects the cryptocurrency and fintech sectors, with secondary targeting of South Korean, Japanese, and US financial institutions. Data exfiltration includes private keys, wallet seeds, and API credentials, leading to unauthorized fund transfers and account takeovers.

🛡️ Mitigation

Organizations should apply Microsoft security patches for CVE-2023-36884, CVE-2021-40444, and CVE-2024-38112 immediately. Deploy detection rules using YARA signatures (Talos published rules in July 2024) and monitor for the specific registry keys, scheduled tasks, and User-Agent strings listed above. Enable PowerShell logging and block outbound connections to known malicious domains via TI feeds from CISA and CrowdStrike.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.