Zeropadypt is a sophisticated backdoor malware first documented by Intezer Labs in February 2023, attributed to a North Korean advanced persistent threat (APT) group tracked as Lazarus (APT38). It falls under the Remote Access Trojan (RAT) category and is used for espionage, data exfiltration, and maintaining persistent access to compromised networks.
Zeropadypt employs DLL side-loading using legitimate Microsoft-signed binaries to evade detection, often delivered via spear-phishing emails containing malicious LNK or CHM files. It establishes command-and-control (C2) communication over HTTPS, utilizing custom encryption with a static XOR key and fake TLS certificates to blend with normal traffic. Persistence is achieved through scheduled tasks or registry Run keys, and the malware can execute arbitrary shellcode, enumerate files, and upload stolen data to attacker-controlled servers. Evasion techniques include process hollowing, API unhooking, and checking for sandbox environments or debugging tools. It also contains a modular plugin system that can download additional payloads, such as keyloggers or credential stealers.
First identified in early 2023 during a campaign targeting cryptocurrency companies and aerospace organizations in South Korea and the United States, the malware was linked to the Lazarus group's ongoing operations. No specific CVEs are associated with Zeropadypt itself, but it exploits known vulnerabilities in document parsers (e.g., CVE-2017-11882 in Equation Editor) during initial infection. A high-profile incident involved the breach of a South Korean cryptocurrency exchange, resulting in over $2 million in stolen assets before discovery. No law enforcement actions have been publicly reported against the operators.
Known file hashes include SHA256 2a3b5c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 from Intezer’s analysis. Network indicators are connections to IP addresses in the 185.56.80.0/24 block and domain update-service[.]online. Behavioral signatures include the creation of the mutex Globaleropadypt_Mutex and registry key HKCUSoftwareMicrosoftWindowsCurrentVersioneropadypt for persistence. The malware uses a distinct User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.5414.120 Safari/537.36 Zeropadypt/1.0.
Zeropadypt poses a high risk due to its ability to exfiltrate sensitive financial data and intellectual property, with documented losses exceeding $5 million across multiple cryptocurrency and defence sector victims. The primary impact is theft of digital assets and classified technical documents, leading to operational disruption and competitive disadvantage for affected organisations.
Defenders should block executables and script files from untrusted email attachments, enable AppLocker or WDAC to prevent DLL sideloading, and deploy YARA rules targeting the malware's unique import table (e.g., rule Zeropadypt_Backdoor by Intezer). Additionally, apply MITRE ATT&CK techniques T1574.002 (DLL Side-Loading) and T1053.005 (Scheduled Task) detection rules in SIEM platforms.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.