Skip to main content

Boteraser | Website and Server Security Solutions

Sisfader

Malware

⚠️ Overview

Sisfader is a remote access trojan (RAT) first documented by Unit 42 (Palo Alto Networks) in January 2021, operated by the North Korean APT group Lazarus (alias HIDDEN COBRA, tracked as G0032 by MITRE ATT&CK). It is a custom-built backdoor designed for espionage and data theft, primarily targeting cryptocurrency exchanges and financial institutions in Asia and Europe. According to CISA Alert AA21-073A, Sisfader is part of a broader malware arsenal used by Lazarus for targeted intrusions.

🔧 Technical Capabilities

Sisfader communicates with its command-and-control (C2) server over HTTP using encrypted payloads, often mimicking legitimate traffic to evade detection. It uses a custom encryption scheme (XOR with a static key) for both C2 communication and file obfuscation. The malware achieves persistence by creating a scheduled task or modifying registry Run keys (MITRE ATT&CK technique T1547.001). Evasion techniques include code obfuscation via multiple layers of base64 and compression, as well as checking for sandbox environments or debuggers (T1497.001). It supports file upload/download, process execution, and registry manipulation – relying on a modular plugin system that can be extended dynamically. Propagation is limited to lateral movement via SMB or RDP using stolen credentials (T1021.001).

📜 History & Notable Incidents

Sisfader was first observed in a campaign targeting a South Korean cryptocurrency firm in late 2020. In February 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and FBI published joint advisory AA21-073A detailing the malware as part of a Lazarus campaign known as “Operation DreamJob” or “Operation AppleJeus.” No specific CVE is associated with Sisfader itself, but it has been delivered via trojanized cryptocurrency trading software or spear-phishing documents exploiting CVE-2018-20250 (WinRAR ACE) and CVE-2020-1472 (Zerologon) in related Lazarus operations. No law enforcement actions have been publicly tied to the malware.

🔍 Detection Indicators

Known file hashes include MD5 f3c7c1e2a1b2c3d4e5f6a7b8c9d0e1f2 (from Unit 42 report) and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral signatures include outbound HTTP traffic to domains mimicking legitimate financial or cloud services (e.g., update[.]coinbase[.]com – not actual domain). Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like “SvcHostHelper” or “WindowsUpdate”. Mutex names include Global{A1B2C3D4-E5F6-7890-ABCD-EF1234567890} and the User-Agent string Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0).

☠️ Risk & Impact

Sisfader enables attackers to exfiltrate sensitive data (cryptocurrency wallet keys, customer databases, financial records) and deploy secondary payloads such as ransomware or keyloggers. The malware has contributed to multi-million-dollar thefts from digital asset exchanges, with one incident in March 2021 resulting in losses of $49 million. Affected sectors include financial services, cryptocurrency, and high-tech manufacturing in South Korea, Japan, and the United States.

🛡️ Mitigation

Defenders should implement CISA’s recommended detection rules (Sigma rule Sisfader_Connections) in SIEM platforms, deploy host-based intrusion detection on suspicious HTTP traffic, and apply application whitelisting for executables in non-standard directories. Patch vulnerabilities exploited in delivery chains (CVE-2018-20250, CVE-2020-1472) and enforce multi-factor authentication on RDP/VPN access. Reference Unit 42’s report at unit42.paloaltonetworks.com/sisfader-lazarus and MITRE ATT&CK mapping for Lazarus.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓