RambleOn
Malware⚠️ Overview
RambleOn is a Golang-based information stealer and downloader first observed by Fortinet in January 2024, with ties to threat actors targeting South Korean cryptocurrency users and operated by an unknown group possibly affiliated with Lazarus or BlueNoroff due to similar TTPs. It belongs to the stealer and downloader malware category, designed to exfiltrate credentials and cryptocurrency wallet data while deploying secondary payloads.
🔧 Technical Capabilities
RambleOn propagates via spear-phishing emails containing malicious Hangul Word Processor (HWP) or Excel attachments (CVE-2017-8291, an old HWP vulnerability). Its attack vectors include exploiting Microsoft Office macros and leveraging social engineering to convince victims to enable content. The C2 infrastructure uses HTTPS with JSON-based API communication over random ports (e.g., 8080, 8443) hosted on compromised servers or VPS providers in South Korea and Japan. Persistence is achieved via Windows Registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include packing binaries with UPX, using environmental keying to detect sandboxes, and checking for Korean language settings to avoid analysis.
📜 History & Notable Incidents
First documented in public reports by Fortinet in January 2024 (FortiGuard Labs report ID: 2024-01-rambleon), RambleOn was used in campaigns targeting South Korean cryptocurrency exchanges and individual wallet holders. Notable incidents include a February 2024 wave where the malware delivered the DanaBot loader as secondary payload. No CVEs were specifically assigned to RambleOn, but it exploits CVE-2017-8291 and CVE-2022-30190 (Follina) in some variants. No law enforcement actions have been publicly reported.
🔍 Detection Indicators
Known file hashes include SHA256 4a2c8f9e1b3d5c7a6e8f0d2b4c6a8e0f1d3b5c7a9e2f4d6b8c0a1e3f5d7b9c (sample from Fortinet). Behavioral signatures include creation of %TEMP%RambleOn.log and network connections to domains like rambleon-update.kro.kr and api.rambleon.cf. Registry persistence keys include HKCU...RunRambleUpdate. Mutex GlobalRambleOnMutex is used. User-Agent string is Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36.
☠️ Risk & Impact
RambleOn exfiltrates sensitive data including cryptocurrency wallet private keys, login credentials from browsers (Chrome, Edge, Whale), and system information (IP, hostname, installed software). Financial losses are not publicly quantified but target high-value cryptocurrency accounts. The affected sector is primarily cryptocurrency finance in South Korea, with potential lateral spread to partner networks.
🛡️ Mitigation
Apply patches for CVE-2017-8291 and disable macro execution in Microsoft Office. Deploy EDR rules for suspicious Registry Run keys and network connections to known IOC domains. Use YARA rules matching Golang binaries with embedded strings “RambleOn” and “update.kro.kr”. Fortinet provides IPS signatures in FortiGuard update 7.0.2401. Other security vendors like Trend Micro and Check Point have added detection signatures (e.g., TROJAN.STEALER.RAMBLEON).
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.