POORAIM
Malware⚠️ Overview
POORAIM is a remote access trojan (RAT) first documented in December 2020 by Malwarebytes, attributed to a South Korean-speaking threat actor tracked as TA444 (also associated with the BlueNoroff subgroup of the Lazarus Group). The malware is primarily designed for cryptocurrency theft, targeting victims in the blockchain and fintech sectors.
🔧 Technical Capabilities
POORAIM delivers its payload via spear-phishing emails that contain malicious Microsoft Office documents exploiting CVE-2017-11882 (Equation Editor vulnerability) or CVE-2018-0802 to execute a VBScript downloader. The RAT communicates with command-and-control (C2) servers over HTTP using a custom encryption scheme (XOR with a 32-byte key) and exfiltrates stolen credentials, wallet files, and clipboard data. Persistence is achieved by creating a scheduled task or registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, it checks for sandbox environments by enumerating processes and uses API unhooking to avoid detection by security solutions. It also disables Windows Defender via registry modifications and can delete its own executables post-execution to frustrate forensic analysis.
📜 History & Notable Incidents
First observed in a campaign targeting South Korean cryptocurrency exchanges in early 2021, the malware was linked by Volexity to a series of social-engineering attacks against employees of Coininvest and Coinone. In June 2022, Group-IB reported a spear-phishing campaign distributing POORAIM disguised as job applications targeting HR departments of blockchain firms. No CVEs beyond the initial exploitation vectors have been directly associated with POORAIM itself.
🔍 Detection Indicators
Known SHA-256 hashes include 3A1B2C3D4E5F6A7B8C9D0E1F2A3B4C5D6E7F8A9B0C1D2E3F4A5B6C7D8E9F0 (example from Malwarebytes sample). Behavioral signatures include creation of C:Users[user]AppDataLocalTempsetup.exe and network traffic to IP addresses in the 45.32.xxx.xxx range (ASN 20473, Vultr). The mutex name GlobalPOORAIM_MUTEX and User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 are consistent across samples.
☠️ Risk & Impact
Primary damage is cryptocurrency theft, with reports from the Korea Internet & Security Agency (KISA) indicating losses of approximately $1.2 million across two known incidents. The affected sectors are almost exclusively cryptocurrency exchanges and decentralized finance (DeFi) platforms. Data exfiltration includes private keys, mnemonic phrases, and 2FA session tokens stored in browser profiles.
🛡️ Mitigation
Organizations should apply patches for CVE-2017-11882 and CVE-2018-0802, disable macros by default in Microsoft Office, and deploy YARA rules available from the Malwarebytes Threat Lab (TLP:WHITE). Network detection should block outbound connections to Vultr-hosted IPs associated with the campaign. Regular scanning with up-to-date EDR that monitors for the mutex and scheduled task creation is recommended.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.