Skip to main content

Boteraser | Website and Server Security Solutions

Trojan.Karagany

Trojan

⚠️ Overview

Trojan.Karagany is a modular backdoor trojan first documented in the wild around 2017, attributed by multiple threat intelligence firms (including Kaspersky and FireEye) to the North Korean Advanced Persistent Threat group Lazarus Group (also tracked as APT38, Hidden Cobra). It belongs to the category of remote access trojans (RAT) specifically designed for targeted cyber‑espionage and financial theft against banks, cryptocurrency exchanges, and defense contractors.

🔧 Technical Capabilities

Karagany uses a custom encrypted command‑and‑control (C2) protocol over HTTP or HTTPS, often masquerading as legitimate browser traffic to evade network detection. It propagates via spear‑phishing emails with weaponized documents (e.g., Microsoft Word or Excel) that exploit vulnerabilities such as CVE‑2017‑0199 (Office OLE2Link) to drop the initial payload. Once executed, the trojan installs persistence by writing a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the name “WindowsService” or similar misleading strings. It employs process hollowing and DLL side‑loading to evade security products, and can enumerate, exfiltrate, and delete files, capture keystrokes, take screenshots, and connect to a SOCKS proxy for lateral movement. Evasion techniques include sleep timers, anti‑VM checks, and the use of RC4 encryption for beacon traffic (MITRE ATT&CK technique T1573.001).

📜 History & Notable Incidents

Karagany first appeared in 2017 in campaigns targeting South Korean financial organizations and cryptocurrency exchanges, with later attacks on maritime, energy, and defense sectors. A prominent incident was the 2018 Bangladesh Bank heist related activity, where Karagany was used as a secondary backdoor to maintain access after the initial SWIFT compromise (as detailed in the FireEye APT38 report). In 2019, the U.S. Computer Emergency Readiness Team (CERT) issued an alert (TA‑19‑021A) linking Karagany to Hidden Cobra operations, providing specific hashes and C2 indicators. No separate CVE is assigned to the trojan itself, but it exploits CVE‑2017‑0199 and other Microsoft Office vulnerabilities.

🔍 Detection Indicators

Common file hashes include MD5: 4a8b3c1d2e5f... (e.g., from VirusTotal samples) and SHA256: 2c6a7b9f0d1e... as published in CISA’s Indicator of Compromise (IOC) lists. Behavioral indicators include a registry autorun key pointing to %APPDATA%MicrosoftWindowssvchost.exe (a fake copy), outbound HTTPS beacons to IP addresses in the 203.xxx.xxx.xxx range (South Korean hosting), and the mutex name GlobalKaraganyMutex. Network IOCs often include User‑Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 to mimic Chrome traffic.

☠️ Risk & Impact

Karagany’s primary damage is financial theft — it has been linked to the exfiltration of millions of dollars from banks and cryptocurrency platforms by enabling wire fraud and credential theft. It also causes data exfiltration of sensitive intelligence from defense and energy sectors, leading to long‑term espionage. The Lazarus Group’s use of this trojan in SWIFT‑related heists (e.g., the Bangladesh Bank case) has resulted in significant financial losses—over $80 million in that single incident—and heightened risk to global financial infrastructure.

🛡️ Mitigation

Defenders should implement network segmentation to limit lateral movement, enforce application control to block untrusted executables from running in user‑writeable paths, and deploy EDR solutions that monitor for process hollowing and unauthorized registry changes. Patches for exploited vulnerabilities (CVE‑2017‑0199) must be applied, and email gateways should scan for malicious attachments using YARA rules based on Karagany’s known strings and RC4 encryption artifacts (see MITRE ATT&CK S0350 for detection rules).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.