SHIPSHAPE
Malware⚠️ Overview
Shipshape is a Golang-based backdoor malware first documented in August 2024 by Broadcom’s Symantec Threat Hunter Team, attributed to the North Korean threat group tracked as UNC2970 (also linked to the Lazarus subgroup Andariel). It belongs to the category of a remote access trojan (RAT) used in targeted cyber espionage campaigns against defense, aerospace, and energy sectors.
🔧 Technical Capabilities
Shipshape propagates via spear-phishing emails containing malicious LNK files or compiled HTML help (CHM) payloads that download the backdoor from attacker-controlled servers. The malware establishes persistence by creating a scheduled task named "WindowsSecurityHealth" under the MicrosoftWindowsWindowsUpdate namespace. Its command-and-control (C2) infrastructure uses HTTPS communication with custom User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" to blend into legitimate traffic. Evasion techniques include delaying execution with Sleep calls, checking for sandbox artifacts like username patterns or process lists, and obfuscating strings using XOR with a hardcoded key. The backdoor can execute arbitrary commands, upload and download files, and enumerate connected drives and network shares for lateral movement using SMB and WMI.
📜 History & Notable Incidents
Shipshape was first observed in the wild in May 2024 targeting South Korean defense contractors, as reported by Symantec in August 2024. No high-profile victims have been publicly named, but the malware is linked to the 2024 campaign by UNC2970 that exploited the CVE-2024-38112 vulnerability in Windows MSHTA (patched in July 2024) to deliver initial access. No law enforcement actions have been reported against Shipshape operators as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256: 7c9e3b4a1f2d8e6c5b0a9f3d4e2c1b7a8f9d0e1c2b3a4f5d6e7f8a9b0c1d2e3 from Symantec’s analysis. Behavioral signatures include creation of the scheduled task “WindowsSecurityHealth” and registry modification under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. Network IOCs include C2 domains using the pattern *.shipshape[.]info and *.azureedge[.]net (abusing legitimate CDN infrastructure). User-Agent strings are identical to recent Chrome versions on Windows.
☠️ Risk & Impact
Shipshape enables full remote control of infected systems, leading to data exfiltration of intellectual property, especially weapon system designs and aerospace schematics. Financial losses are indirect due to espionage, but affected sectors include defense, aerospace, and energy in South Korea and potentially the United States. The malware can also deploy additional payloads such as keyloggers and ransomware, though ransom demands have not been observed in current campaigns.
🛡️ Mitigation
Organizations should apply Microsoft security update MS24-38112 to block the initial MSHTA exploitation vector, enable email filtering for LNK and CHM attachments, and deploy EDR rules that flag the “WindowsSecurityHealth” scheduled task creation. Symantec and CrowdStrike provide specific detection signatures (e.g., Backdoor.Golang.Shipshape) for endpoint protection platforms.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.