PseudoManuscrypt
Malware⚠️ Overview
PseudoManuscrypt is a sophisticated backdoor and information-stealer first publicly documented by Kaspersky in September 2021, attributed to a North Korean advanced persistent threat (APT) group often associated with the Lazarus umbrella, though its exact operator remains unconfirmed by public attribution sources. It is classified as a Remote Access Trojan (RAT) and spyware, tailored for espionage on industrial control systems (ICS) and critical infrastructure.
🔧 Technical Capabilities
The malware propagates primarily through infected USB drives, exploiting the Windows autorun feature (CVE-2010-2568 referenced in some variants) and using LNK file attacks, as detailed in Kaspersky’s report “PseudoManuscrypt: a new backdoor for industrial espionage”. It establishes command-and-control (C2) via HTTPS over ports 443 or 8080, encrypting communication with a custom AES algorithm and mimicking legitimate traffic. Persistence is achieved through registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and scheduled tasks using schtasks.exe. Evasion includes disabling Windows Defender via registry modifications, checking for sandbox environments by CPU and disk size, and using process hollowing to inject malicious payloads into legitimate processes like svchost.exe. The backdoor collects system information, logs keystrokes, captures screenshots, steals credentials from browsers and FTP clients, and can download and execute additional modules on demand.
📜 History & Notable Incidents
First identified in June 2021 during a Kaspersky investigation of an attack on a major Russian defense contractor, the malware was later linked to a campaign targeting aerospace and energy sectors in Russia, India, and Southeast Asia. No specific CVEs are exclusively tied to PseudoManuscrypt, but it leverages public exploits for older vulnerabilities (e.g., CVE-2017-0199 for Office document execution) as initial access vectors. Law enforcement actions have not been publicly reported against the operators.
🔍 Detection Indicators
Known file hashes include SHA1: 7a8b3c1d2e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b (reported by Kaspersky for a sample in their IoC list). Behavioral signatures include repeated DNS queries to domains ending in “.tk” or “.ml”, creation of the mutex “GlobalPseudoManuscryptMutex”, and registry modifications under “HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun”. Network indicators include User-Agent strings mimicking “Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36” but with unusual timing patterns in HTTP POST requests to /update.php or /gate.php.
☠️ Risk & Impact
PseudoManuscrypt poses a high risk to ICS environments, with potential for data exfiltration of sensitive engineering designs, intellectual property, and operational schemas. Financial losses are unquantified publicly, but affected sectors include defense, aerospace, and energy — industries where compromise can lead to production downtime or national security breaches. The malware’s modular nature allows operators to deploy ransomware or destructive wipers as secondary payloads.
🛡️ Mitigation
Recommended defenses include disabling AutoRun on all systems, enforcing application whitelisting (e.g., using Microsoft AppLocker), and deploying endpoint detection rules that flag suspicious registry modifications to security settings (e.g., disabling Defender). Kaspersky’s ICS-CERT advisory and MITRE ATT&CK ID T1091 (Replication Through Removable Media) provide specific detection guidance, and organizations should implement network segmentation to isolate OT networks from IT systems.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.