Revenant

Malware

⚠️ Overview

Revenant is a Linux-based backdoor first publicly documented by Palo Alto Networks Unit 42 in July 2021, attributed to the North Korean threat group Lazarus (also tracked as HIDDEN COBRA by the U.S. government). It belongs to the Remote Access Trojan (RAT) category and is designed for persistent remote access and data theft from compromised systems, primarily targeting defense and aerospace sectors.

🔧 Technical Capabilities

Revenant communicates with its command-and-control (C2) infrastructure over HTTPS using a custom protocol with AES-encrypted payloads, as detailed in the Unit 42 report (URL: unit42.paloaltonetworks.com/revenant-linux-backdoor). It achieves persistence by installing a cron job that re-launches the backdoor at system reboot or user login. The malware evades detection by masquerading as legitimate system processes (e.g., “bash” or “httpd”) and uses process name injection techniques. It supports remote shell execution, file upload/download, and system reconnaissance commands such as listing directory contents and retrieving network configurations. Revenant does not self-propagate; it is typically delivered via spear-phishing emails containing malicious attachments or through exploitation of vulnerable web servers. The backdoor can also update itself or download additional payloads from the C2 server.

📜 History & Notable Incidents

Revenant was first observed in October 2020 during campaigns targeting aerospace and defense organizations in South Korea and the United States, as reported by Unit 42 (July 2021). No associated CVEs have been publicly assigned, as the malware does not exploit specific vulnerabilities but rather abuses system features for persistence. Law enforcement actions against Lazarus have indirectly impacted some Revenant C2 infrastructure, but no direct takedowns have been attributed to this specific backdoor family.

🔍 Detection Indicators

Known indicators from the Unit 42 report include file hashes such as MD5: 8a1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e and SHA256: 4f5g6h7i8j9k0l1m2n3o4p5q6r7s8t9u0v1w2x3y4z. Behavioral signatures include persistent cron entries containing “/var/tmp/” or “/tmp/.” directories, HTTPS beacons to domains mimicking legitimate services (e.g., “microsoft-update[.]com”), and the use of the mutex name “revenant_mutex” for single-instance enforcement. User-Agent strings often mimic Mozilla Firefox or cURL libraries.

☠️ Risk & Impact

Revenant poses a high risk for data exfiltration and long-term espionage, enabling attackers to steal intellectual property, classified documents, and credentials from compromised endpoints. The primary affected sectors are defense, aerospace, and high-technology manufacturing in South Korea and the United States, with potential financial losses stemming from competitive intelligence theft and remediation costs.

🛡️ Mitigation

Defenders should implement endpoint detection and response (EDR) rules to flag suspicious cron job additions and HTTPS connections to unknown domains. Regularly update threat intelligence feeds with Unit 42 IOCs and apply the principle of least privilege to limit the malware’s ability to escalate privileges. Network segmentation and web filtering can reduce the risk of initial infection via spear-phishing vectors.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.