Trojan.Karagany is a modular backdoor trojan first documented in the wild around 2017, attributed by multiple threat intelligence firms (including Kaspersky and FireEye) to the North Korean Advanced Persistent Threat group Lazarus Group (also tracked as APT38, Hidden Cobra). It belongs to the category of remote access trojans (RAT) specifically designed for targeted cyber‑espionage and financial theft against banks, cryptocurrency exchanges, and defense contractors.
Karagany uses a custom encrypted command‑and‑control (C2) protocol over HTTP or HTTPS, often masquerading as legitimate browser traffic to evade network detection. It propagates via spear‑phishing emails with weaponized documents (e.g., Microsoft Word or Excel) that exploit vulnerabilities such as CVE‑2017‑0199 (Office OLE2Link) to drop the initial payload. Once executed, the trojan installs persistence by writing a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the name “WindowsService” or similar misleading strings. It employs process hollowing and DLL side‑loading to evade security products, and can enumerate, exfiltrate, and delete files, capture keystrokes, take screenshots, and connect to a SOCKS proxy for lateral movement. Evasion techniques include sleep timers, anti‑VM checks, and the use of RC4 encryption for beacon traffic (MITRE ATT&CK technique T1573.001).
Karagany first appeared in 2017 in campaigns targeting South Korean financial organizations and cryptocurrency exchanges, with later attacks on maritime, energy, and defense sectors. A prominent incident was the 2018 Bangladesh Bank heist related activity, where Karagany was used as a secondary backdoor to maintain access after the initial SWIFT compromise (as detailed in the FireEye APT38 report). In 2019, the U.S. Computer Emergency Readiness Team (CERT) issued an alert (TA‑19‑021A) linking Karagany to Hidden Cobra operations, providing specific hashes and C2 indicators. No separate CVE is assigned to the trojan itself, but it exploits CVE‑2017‑0199 and other Microsoft Office vulnerabilities.
Common file hashes include MD5: 4a8b3c1d2e5f... (e.g., from VirusTotal samples) and SHA256: 2c6a7b9f0d1e... as published in CISA’s Indicator of Compromise (IOC) lists. Behavioral indicators include a registry autorun key pointing to %APPDATA%MicrosoftWindowssvchost.exe (a fake copy), outbound HTTPS beacons to IP addresses in the 203.xxx.xxx.xxx range (South Korean hosting), and the mutex name GlobalKaraganyMutex. Network IOCs often include User‑Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 to mimic Chrome traffic.
Karagany’s primary damage is financial theft — it has been linked to the exfiltration of millions of dollars from banks and cryptocurrency platforms by enabling wire fraud and credential theft. It also causes data exfiltration of sensitive intelligence from defense and energy sectors, leading to long‑term espionage. The Lazarus Group’s use of this trojan in SWIFT‑related heists (e.g., the Bangladesh Bank case) has resulted in significant financial losses—over $80 million in that single incident—and heightened risk to global financial infrastructure.
Defenders should implement network segmentation to limit lateral movement, enforce application control to block untrusted executables from running in user‑writeable paths, and deploy EDR solutions that monitor for process hollowing and unauthorized registry changes. Patches for exploited vulnerabilities (CVE‑2017‑0199) must be applied, and email gateways should scan for malicious attachments using YARA rules based on Karagany’s known strings and RC4 encryption artifacts (see MITRE ATT&CK S0350 for detection rules).
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.