PULSE NAME
Three Lazarus RATs coming for your cheese
WHITE Lazarus AlienVault 2025-09-02 Modified: 2025-10-02
64
IOCs
HIGH VOLUME
This report analyzes three remote access trojans (RATs) used by a Lazarus subgroup targeting financial and cryptocurrency organizations. The RATs, named PondRAT, ThemeForestRAT, and RemotePE, were observed during incident response cases. PondRAT is a simple RAT used as an initial payload, while ThemeForestRAT offers more functionality and operates in-memory. RemotePE is a more advanced RAT deployed in later attack stages. The actor uses social engineering for initial access and employs various tools for network discovery. The report details the RATs' capabilities, command and control mechanisms, and similarities to previously known malware families. It highlights the actor's persistent threat and evolving tactics in targeting high-value financial targets.
Indicators of Compromise (11 / 64 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 1a6366a45cb892cf76af8ba25d114334f1e34532 2025-09-02
FileHash-SHA1 24cc64543f339d701b7fe6c7e05f41cb54c9dc83 2025-09-02
FileHash-SHA1 58b0516d28bd7218b1908fb266b8fe7582e22a5f 2025-09-02
FileHash-SHA1 6f391d282a37b770abcedd08c4c0e2156076cd8e 2025-09-02
FileHash-SHA1 7b6e6487b803bbe85d7466b89da51a269fa4fc29 2025-09-02
FileHash-SHA1 10da1920639e009539ac4e8b8c740a2c335bf630 2025-09-02
FileHash-SHA1 442f4abac74d844256e3ff60f929b358ded71881 2025-09-02
FileHash-SHA1 56f9b97fee195ed8dea39552eac288aa58cfaf48 2025-09-02
FileHash-SHA1 bddd1fb74bbed46f07743af28cb1e1468df3d3bd 2025-09-02
FileHash-SHA1 bef8714787a76d33d74dc23e7c750e74b57f6f04 2025-09-02
FileHash-SHA1 f8df313a370bc856a0f2c05c6d27e56c56b7448f 2025-09-02