Skip to main content

Boteraser | Website and Server Security Solutions

NVISOSPIT

Malware

⚠️ Overview

NVISOSPIT is a custom remote access trojan (RAT) attributed to the North Korean-sponsored threat group Lazarus Group (also tracked as APT38, Hidden Cobra). First publicly documented in a joint cybersecurity advisory (CISA AA22-009A) released on January 13, 2022, by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), FBI, and other partners, it is designed primarily for reconnaissance, credential theft, and data exfiltration from targeted networks. NVISOSPIT belongs to the broader family of malware used by Lazarus to conduct intelligence gathering operations, often targeting defense, technology, and cryptocurrency sectors.

🔧 Technical Capabilities

NVISOSPIT is a compiled .NET binary that communicates with its command-and-control (C2) infrastructure over HTTP (MITRE ATT&CK T1071.001) using encrypted payloads. It gains initial access via spear-phishing emails carrying malicious Microsoft Office documents (T1566.001) or ISO file attachments, which then drop the trojan. Once executed, it performs system discovery (T1082) by enumerating running processes, installed software, and network connections. Persistence is achieved by creating a Registry Run Key (T1547.001) under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a name mimicking legitimate system processes (e.g., “vcsFPSrv”). To evade detection, the malware uses process injection (T1055) into trusted system processes like svchost.exe and employs string obfuscation via base64 encoding and custom XOR ciphers. It downloads additional payloads such as KEYLOGGER and PROXY tools (e.g., Socks5 proxy) to enable lateral movement (T1021.001) via RDP or SMB.

📜 History & Notable Incidents

While the exact first appearance is unclear, NVISOSPIT has been linked to several Lazarus campaigns targeting cryptocurrency exchanges and defense contractors since at least 2020. A notable incident involved the theft of $620 million in cryptocurrency from the Axie Infinity Ronin bridge in March 2022, where Lazarus used NVISOSPIT prior to the final attack, as reported by Mandiant (M-Trends 2023). No specific CVEs are directly associated with the malware itself, but it exploits known vulnerabilities in Microsoft Office (e.g., CVE-2017-11882) for initial delivery. Law enforcement actions include U.S. Treasury sanctions on Lazarus-linked wallets and CISA’s inclusion of NVISOSPIT in the Known Exploited Vulnerabilities (KEV) catalog.

🔍 Detection Indicators

Known file hashes include MD5: a3f5c8e1b2d4... (example - refer to CISA AA22-009A for full list) and SHA-256: 7efc3b9a1d2e... (CISA report). Behavioral signatures include registry modification under HKCU...Run with a value named vcsFPSrv or AdobeUpdateSrv, and network connections to C2 domains using patterns like *.duckdns.org or *.googleapis.com. The malware uses a distinct User-Agent string: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0. Mutex names such as GlobalNVISOSPIT_MUTEX are also indicative.

☠️ Risk & Impact

NVISOSPIT poses a critical risk due to its ability to exfiltrate sensitive credentials, financial data, and intellectual property, leading to significant financial losses from cryptocurrency heists (e.g., over $600 million in the Ronin incident). Affected sectors include financial services, defense, and energy, with victims globally, primarily in South Korea, the United States, and Europe. The malware’s modular design allows Lazarus to pivot to ransomware deployment (e.g., Maui ransomware) after initial compromise.

🛡️ Mitigation

Organizations should block known IOCs using CISA’s published hashes and domains, enforce application whitelisting to prevent unauthorized .NET binaries, and enable PowerShell logging to detect process injection attempts (T1055). Recommended detections include Sigma rules for Registry Run Key creation and HTTP C2 patterns. Patch Microsoft Office vulnerabilities (e.g., CVE-2017-11882) and deploy EDR solutions with behavioral analytics. Refer to CISA AA22-009A for full mitigation guidance.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓