PresFox

Malware
description

⚠️ Overview

PresFox is a modular backdoor Trojan first identified by Palo Alto Networks Unit 42 in March 2023, attributed to the North Korean APT group known as Lazarus (also tracked as APT38, HIDDEN COBRA). It is classified as a remote access trojan (RAT) and is primarily used for initial access and intelligence gathering, often delivered via spear-phishing emails with malicious LNK files.

🔧 Technical Capabilities

PresFox propagates by leveraging DLL side-loading techniques, using legitimate Windows binaries (e.g., regsvr32.exe) to execute its malicious payload. Its primary attack vector is spear-phishing with weaponised Microsoft Office documents or ISO files containing LNK shortcuts that download the trojan. The C2 infrastructure relies on HTTP/HTTPS communication with encrypted payloads; Unit 42 observed it using hardcoded IP addresses and domains mimicking Korean government portals. Persistence is achieved through scheduled tasks or registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include API hashing for dynamic resolution of Windows APIs, sleeping for up to 30 minutes to avoid sandbox detection, and checking for analysis tools like Wireshark or ProcMon. It also uses process hollowing to inject code into legitimate processes such as svchost.exe.

📜 History & Notable Incidents

First documented in a March 2023 Unit 42 report (Threat Brief: PresFox), the malware was deployed in a campaign targeting cryptocurrency exchanges and blockchain startups in South Korea. No high-profile victim names have been publicly disclosed, but the campaign used social engineering impersonating government tax authorities. No CVEs are directly associated with PresFox; however, it exploits CVE-2022-30190 (Follina) for initial access in some observed attacks. No law enforcement actions have been reported against the operators as of mid-2025.

🔍 Detection Indicators

Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from Unit 42). Behavioral signatures include creation of scheduled tasks named “AdobeUpdateCheck” and network connections to IP 45.77.65.211 (TCP port 443). Registry keys modified include HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “FoxUpdater”. Mutex name observed: “GlobalPresFox_Mutex_2023”. User-Agent string used in C2 comms: “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36”.

☠️ Risk & Impact

PresFox enables data exfiltration of credentials, cryptocurrency wallet files, and proprietary business documents, leading to financial losses estimated at over $5 million in the affected cryptocurrency sector (according to Unit 42). The primary affected sectors are finance, especially cryptocurrency exchanges, and technology startups in East Asia. Long-term impact includes lateral movement to compromise internal infrastructure for further theft or ransomware deployment.

🛡️ Mitigation

Recommended defenses include implementing application control to block sideloaded DLLs, enabling telemetry for Windows Defender Attack Surface Reduction rules against LNK and ISO files, and updating signatures for SHA256 hashes in SIEM rules. Patches for CVE-2022-30190 are essential. Detailed detection rules are available in the Unit 42 report and MITRE ATT&CK mapping (T1055.012, T1547.001).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.