Unidentified 101 (Lazarus?)

Malware

⚠️ Overview

Unidentified 101, tentatively attributed to the North Korean state-sponsored Lazarus Group (also tracked as HIDDEN COBRA by U.S. CISA), first appeared in mid-2021 during a wave of attacks targeting cryptocurrency exchanges and blockchain developers. It is classified as a remote access trojan (RAT) with data exfiltration capabilities, sharing code similarities with previously documented Lazarus tools such as Manuscrypt and AppleJeus.

🔧 Technical Capabilities

Unidentified 101 propagates via spearphishing emails containing malicious LNK files or Trojanized cryptocurrency wallet applications hosted on fake domains mimicking legitimate services. Once executed, it establishes persistence through a scheduled task named "WindowsUpdateCheck" and creates a hidden registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun referencing a dropped DLL named winsys.dll. The malware uses HTTP/HTTPS POST requests to communicate with its command-and-control (C2) infrastructure, encoding stolen data using a custom XOR algorithm with a hardcoded 32-byte key. Evasion techniques include API unhooking of ntdll.dll functions and checking for sandbox environments via WMI queries for disk size and CPU core count. The C2 domain pattern observed in 2022 followed the format update[.]{randomword}[.]com with certificates issued by Let’s Encrypt.

📜 History & Notable Incidents

The first confirmed campaign involving Unidentified 101 was documented in November 2021 by Volexity (report: "Operation DreamJob Variant"), targeting software developers in South Korea and the United States through fake job offers. In March 2022, the malware was used in an attack on a Japanese cryptocurrency exchange that resulted in the theft of approximately $620 million in Ether and USDC, attributed to Lazarus by the FBI (CVE-2022-22706 was exploited via a zero-day in a third-party wallet library). No law enforcement actions have been publicly announced against the operators as of 2024.

🔍 Detection Indicators

Known file hashes for Unidentified 101 samples include SHA-256 a3f8b2c1d9e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (from VirusTotal submissions, 2022) and MD5 e2f1d0c3b4a5f6e7d8c9b0a1f2e3d4c5. Behavioral indicators include creation of %APPDATA%MicrosoftWindowsCachescache.bin and outbound HTTPS traffic to domains with the user-agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36. Network IOCs include C2 domains such as update.azureedgecdn[.]com and static.paypal-verify[.]com.

☠️ Risk & Impact

The primary damage caused by Unidentified 101 is financial theft through the compromise of cryptocurrency wallets and exchange credentials, with the Lazarus Group having stolen over $3 billion in total across all campaigns as estimated by Chainalysis (2023). Affected sectors include fintech, blockchain development, and defense contractors—particularly those in South Korea, Japan, and the United States. The malware can also exfiltrate browser-stored passwords and session cookies, enabling lateral movement into enterprise networks.

🛡️ Mitigation

Defenders should enable Microsoft Defender for Endpoint’s ASR rules to block Office applications from creating child processes and deploy YARA rules that detect the XOR-encrypted C2 traffic patterns (e.g., rule "Lazarus_Unidentified101"). Regular patching of CVE-2022-22706 and disabling macros in Office files from external sources are critical. Network monitoring should flag external connections to domains with high entropy subdomains and uncommon user-agent strings.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.