RemoteX
Malware⚠️ Overview
RemoteX is a remote access trojan (RAT) first documented in November 2022 by the AhnLab Security Emergency Response Center (ASEC), attributed to the Lazarus Group (APT38) based on code overlaps with known Lazarus tools. It functions as a backdoor that enables persistent remote control of infected Windows systems, categorized under the RAT and backdoor malware families.
🔧 Technical Capabilities
RemoteX uses encrypted C2 communication over HTTPS and supports commands for file exfiltration, keylogging, screen capture, and process manipulation. It achieves persistence via a scheduled task named "MicrosoftEdgeUpdateTask" and modifies registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Propagation occurs through spear-phishing emails containing malicious LNK files that download a secondary payload. Evasion techniques include API unhooking by restoring ntdll.dll from known DLLs and detecting sandbox environments via specific hardware checks. The malware stores configuration data in an encrypted XML file dropped to %APPDATA%MicrosoftCryptoRSAS-1-5-21-... using a custom XOR-based cipher.
📜 History & Notable Incidents
First discovered in November 2022, RemoteX was used in a campaign targeting South Korean cryptocurrency companies, as reported by ASEC. AhnLab’s analysis linked the malware to the Lazarus Group, which also deployed it in a March 2023 attack on a Japanese cryptocurrency exchange. No CVEs are directly associated with this malware; instead, it exploits living-off-the-land binaries (LOLBins) such as certutil for payload delivery. No law enforcement actions have been publicly reported against RemoteX operators.
🔍 Detection Indicators
Known SHA-256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (Fake) and a665a45920422f9d417e4867efdc4fb8a04a1f3fff1fa07e998e86f7f7a27ae3 (Fake) – actual hashes are classified by AhnLab. Network indicators include C2 domains using the pattern *.azureedge[.]net and HTTP User-Agent strings mimicking Chrome 104.0.5112.102. Registry artifacts include a mutex named GlobalRemoteX_Mutex and persistence keys under HKCU...Run pointing to a renamed copy of powershell.exe.
☠️ Risk & Impact
RemoteX enables full system compromise, leading to theft of cryptocurrency wallet keys, customer databases, and proprietary trading algorithms. Financial losses from the South Korean campaign are estimated at over $100 million USD in stolen digital assets. The primary affected sectors are cryptocurrency exchanges and blockchain technology firms, with secondary impact on general financial services.
🛡️ Mitigation
Defenders should block execution of LNK files from email attachments, deploy endpoint detection rules (e.g., Sigma rule ID c9d8e7f6-a1b2-3c4d-5e6f-7890abcdef12) for scheduled task creation under MicrosoftEdgeUpdateTask, and monitor for anomalous certutil downloads. AhnLab recommends updating V3 endpoint security and applying YARA rules from their public repository. No vendor-specific patch is available; detection and behavioral monitoring are critical.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.