← Back to Pulse Feed
PULSE DETAIL
This report analyzes three remote access trojans (RATs) used by a Lazarus subgroup targeting financial and cryptocurrency organizations. The RATs, named PondRAT, ThemeForestRAT, and RemotePE, were observed during incident response cases. PondRAT is a simple RAT used as an initial payload, while ThemeForestRAT offers more functionality and operates in-memory. RemotePE is a more advanced RAT deployed in later attack stages. The actor uses social engineering for initial access and employs various tools for network discovery. The report details the RATs' capabilities, command and control mechanisms, and similarities to previously known malware families. It highlights the actor's persistent threat and evolving tactics in targeting high-value financial targets.
MITRE ATT&CK & Malware Families
Indicators of Compromise (11 / 64 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 1a6366a45cb892cf76af8ba25d114334f1e34532 | — | 2025-09-02 | |
| FileHash-SHA1 | 24cc64543f339d701b7fe6c7e05f41cb54c9dc83 | — | 2025-09-02 | |
| FileHash-SHA1 | 58b0516d28bd7218b1908fb266b8fe7582e22a5f | — | 2025-09-02 | |
| FileHash-SHA1 | 6f391d282a37b770abcedd08c4c0e2156076cd8e | — | 2025-09-02 | |
| FileHash-SHA1 | 7b6e6487b803bbe85d7466b89da51a269fa4fc29 | — | 2025-09-02 | |
| FileHash-SHA1 | 10da1920639e009539ac4e8b8c740a2c335bf630 | — | 2025-09-02 | |
| FileHash-SHA1 | 442f4abac74d844256e3ff60f929b358ded71881 | — | 2025-09-02 | |
| FileHash-SHA1 | 56f9b97fee195ed8dea39552eac288aa58cfaf48 | — | 2025-09-02 | |
| FileHash-SHA1 | bddd1fb74bbed46f07743af28cb1e1468df3d3bd | — | 2025-09-02 | |
| FileHash-SHA1 | bef8714787a76d33d74dc23e7c750e74b57f6f04 | — | 2025-09-02 | |
| FileHash-SHA1 | f8df313a370bc856a0f2c05c6d27e56c56b7448f | — | 2025-09-02 |