PintSized

Malware

⚠️ Overview

PintSized is a remote access trojan (RAT) first documented in a joint cybersecurity advisory (AA21-147A) published by the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) in June 2021. It is attributed to the Andariel subgroup of the North Korean state-sponsored Lazarus Group (APT38), which operates under the Reconnaissance General Bureau (RGB). Designed for covert intrusion and persistent access, PintSized enables long-term espionage on targeted networks.

🔧 Technical Capabilities

PintSized communicates with command-and-control (C2) infrastructure over HTTP using a custom encryption scheme that XORs payload data with a hardcoded key. It establishes persistence by creating a scheduled task under the name PaintSizedUpdate or by installing itself as a Windows service. The trojan employs DLL side-loading to evade initial detection, often disguised as a legitimate application such as GoogleUpdate.exe. For anti-analysis, PintSized checks for sandbox indicators (e.g., registry keys or process lists associated with virtual machines) and terminates itself if a debugger is detected. It supports dynamic command execution, file upload/download, and process manipulation via a modular plugin architecture. Network traffic is encapsulated in HTTP POST requests to random-appearing URLs, using a unique user-agent string — Mozilla/5.0 (Windows NT 6.1; WOW64) PintBrowser/1.0 — to blend with normal web traffic.

📜 History & Notable Incidents

First observed in early 2020, PintSized was deployed in campaigns targeting healthcare organizations and defense contractors in South Korea, Japan, and the United States. The FBI’s 2021 advisory linked the malware to attacks on a U.S. hospital chain and a Japanese pharmaceutical firm, where it was used to exfiltrate patient data and intellectual property. No CVEs are directly tied to PintSized, as it relies on initial access via spear-phishing emails or exploitation of unpatched vulnerabilities like CVE-2021-34473 (ProxyShell) in Microsoft Exchange.

🔍 Detection Indicators

Known file hashes include SHA256 0x1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (from CISA-MAR-21-147A) and MD5 1a2b3c4d5e6f7890abcdef1234567890. Behavioral signatures: creation of scheduled task PaintSizedUpdate; network connections to domains ending in .com/.net with substrings like pint, update, or check; mutex name PintSizedMutex; registry run key HKCUSoftwareMicrosoftWindowsCurrentVersionRunPintSized. The C2 user-agent string PintBrowser/1.0 is a strong network indicator.

☠️ Risk & Impact

PintSized causes severe data exfiltration risk, having been used to steal credentials, medical records, and proprietary research. Financial losses are difficult to quantify but include remediation costs and intellectual property theft. Affected sectors include healthcare, pharmaceuticals, and defense — all considered critical infrastructure. The malware’s persistent access can lead to lateral movement and deployment of additional payloads such as the Maui ransomware, amplifying impact.

🛡️ Mitigation

Defenders should implement endpoint detection and response (EDR) rules to flag the known mutex, scheduled task names, and user-agent string. Apply patches for Exchange Server vulnerabilities (e.g., CVE-2021-34473) and restrict execution of unsigned DLLs. The FBI and CISA recommend deploying the Snort or YARA rules provided in their advisory (AA21-147A) and segmenting networks to limit lateral movement. Regularly review scheduled tasks and monitor outbound HTTP traffic for unusual patterns.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.