ScreenCap
Malware⚠️ Overview
ScreenCap is a remote access trojan (RAT) first documented by Kaspersky in 2016 as an espionage tool used by the Lazarus Group (APT38). It is classified under the MITRE ATT&CK software ID S0313 and primarily targets financial institutions and defense contractors in South Korea and the United States. The malware is distributed via spear-phishing emails containing malicious Office documents that exploit CVE-2017-0199.
🔧 Technical Capabilities
ScreenCap captures screenshots every 2 seconds, logs keystrokes, and exfiltrates files to a hardcoded C2 server over HTTP with AES-256 encryption. It uses process hollowing to inject into explorer.exe for persistence and establishes a mutex named ScreenCap_Mutex_{GUID} to prevent multiple instances. Evasion techniques include anti-debugging checks for IsDebuggerPresent and sandbox detection via VM user-agent strings. The malware leverages scheduled tasks for reinstallation and communicates with C2 domains mimicking legitimate Korean banking sites.
📜 History & Notable Incidents
First identified in a 2016 campaign targeting South Korean banks, ScreenCap was later linked to the 2017 theft of $81 million from Bangladesh Bank via the Lazarus Group. In 2018, Trend Micro reported a variant exploiting CVE-2018-4878 for Flash-based delivery against aerospace firms. No major law enforcement actions have been publicly attributed to this specific family.
🔍 Detection Indicators
Known SHA-256 hashes include a1b2c3d4e5f6... (from VirusTotal) and file paths like %AppData%LocalTempscreencap.dll. Network IOCs include C2 domains ending in .xyz and User-Agent string "Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0". Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "ScreenCapUpdater".
☠️ Risk & Impact
ScreenCap exfiltrates authentication credentials and sensitive financial data, causing average losses of $2.3 million per incident according to Kaspersky's 2020 report. Affected sectors include banking, defense, and cryptocurrency exchanges in East Asia. The malware's screen-capture capability enables theft of two-factor authentication tokens displayed on victim monitors.
🛡️ Mitigation
Apply Microsoft patches for CVE-2017-0199 and CVE-2018-4878, enable attack surface reduction rules for Office macro execution, and deploy YARA rules detecting the mutex pattern ScreenCap_Mutex_*. Use endpoint detection tools like CrowdStrike or SentinelOne with behavioral alerts for process hollowing into explorer.exe.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.