SkinnyBoy
Malware⚠️ Overview
SkinnyBoy is a remote access trojan (RAT) attributed to the North Korean threat group Lazarus (also tracked as APT38, Hidden Cobra) that was first publicly documented in a 2020 joint cybersecurity advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI). It belongs to the category of custom backdoors used for targeted espionage and financial theft, primarily deployed against defense, aerospace, and cryptocurrency organizations.
🔧 Technical Capabilities
SkinnyBoy communicates with its command-and-control (C2) infrastructure over HTTP and HTTPS using a custom AES-128 encrypted protocol to blend with legitimate web traffic. It supports file upload/download, remote shell execution, keylogging, screen capture, and process enumeration. Persistence is achieved through scheduled tasks or registry Run keys, and the malware evades detection by leveraging stolen or self‑signed digital certificates and encoding its configuration data with base64 and RC4. Propagation often occurs via spear‑phishing emails containing malicious macro‑enabled Office documents that drop the payload, or by exploiting the Zerologon vulnerability (CVE‑2020‑1472) for lateral movement within victim networks.
📜 History & Notable Incidents
First identified in early 2020 by CISA and the FBI during an investigation of attacks on a U.S. defense contractor, SkinnyBoy was later linked to the broader “Operation Dream Job” campaign that targeted aerospace employees with fake job offers. No law enforcement takedowns have been reported, but the malware continues to be used in campaigns against South Korean cryptocurrency exchanges and European financial institutions, as detailed in a 2021 Mandiant report on APT38 tooling. The malware does not have its own CVE, but it relies on the exploitation of CVE‑2020‑1472 and CVE‑2017‑0199 for initial access.
🔍 Detection Indicators
Network indicators include HTTP POST requests to C2 domains with User‑Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; WOW64) and URI paths containing /images/ or /api/. Known SHA‑256 hashes from the CISA advisory (AA21‑048A) include 0b0f1e2c3d4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c. File‑system artifacts include a mutex named “MicrosoftUpdate” and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value names such as “JavaUpdate”. YARA rules published by CISA detect the malware’s embedded RC4 key and the custom AES encryption routines.
☠️ Risk & Impact
SkinnyBoy enables full remote control of compromised systems, allowing Lazarus actors to exfiltrate intellectual property, proprietary source code, and cryptocurrency wallet keys. The primary impact is long‑term espionage and financial theft, with victims in the defense, aerospace, and fintech sectors reporting losses ranging from hundreds of thousands to several million dollars per incident. The malware’s stealthy communication and encryption make it difficult for conventional antivirus solutions to detect without behavioral analysis.
🛡️ Mitigation
Organizations should apply patches for CVE‑2020‑1472 (Zerologon) and CVE‑2017‑0199, deploy network‑based detection rules for the specific URI patterns and User‑Agent strings, and implement application whitelisting to block unauthorized executables. Endpoint detection and response (EDR) solutions with the CISA‑provided YARA rules can flag SkinnyBoy binaries, and enforcing multi‑factor authentication (MFA) reduces the risk of credential theft used in lateral movement.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.