PULSE NAME
Three Lazarus RATs coming for your cheese
WHITE Lazarus AlienVault 2025-09-03 Modified: 2025-10-03
136
IOCs
HIGH VOLUME
This report analyzes three remote access trojans (RATs) used by a Lazarus subgroup targeting financial and cryptocurrency organizations: PondRAT, ThemeForestRAT, and RemotePE. It details an incident response case from 2024 involving social engineering and possible zero-day exploitation. PondRAT is described as a simple initial access tool, while ThemeForestRAT is a more capable memory-only RAT used in conjunction. RemotePE appears to be an advanced RAT deployed in later attack stages. The analysis reveals connections between these tools and previously known Lazarus malware like POOLRAT. The report highlights the actor's persistence, sophistication, and continued threat to financial targets.
Indicators of Compromise (27 / 136 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0d451cd700544d333763089c64fb1f0a 2025-09-03
FileHash-MD5 0d714435e4c4c1f0e7fe20695734e513 2025-09-03
FileHash-MD5 0df2a1f2991d138d60ba0eb2bb77f373 2025-09-03
FileHash-MD5 1410b6bb5e2cf775660fb144528675cc 2025-09-03
FileHash-MD5 2cd0404b633b13979b3a33d631693ba9 2025-09-03
FileHash-MD5 32989b09ebb355f99894622d3af272a0 2025-09-03
FileHash-MD5 52a825b84e1318a3e50d065f78643689 2025-09-03
FileHash-MD5 93ed4656891d36a5b8499e139ba75ab6 2025-09-03
FileHash-MD5 99c4f15a0e46b6c778e336d4aaf6e2dc 2025-09-03
FileHash-MD5 a4ba7c5ed23fe7e9f05a2049383470f3 2025-09-03
FileHash-MD5 a8016f7810cb347c747f46875729f63c 2025-09-03
FileHash-MD5 bcf71bd7ff3af7139e735269008fb9ec 2025-09-03
FileHash-MD5 be3e2c20ff42451b02fc9ad2fce47dff 2025-09-03
FileHash-MD5 c9de787a91c1bc88149bc1349ec80ba8 2025-09-03
FileHash-MD5 d70ab881f617cae03dc7bcc4d0cfc524 2025-09-03
FileHash-MD5 ead0e113b1cfd2929e58dc37f3ae1a49 2025-09-03
FileHash-MD5 f8d23ab58295c2f4474d2bd92606a20d 2025-09-03
FileHash-MD5 19dbffec4e359a198daf4ffca1ab9165 2025-09-03
FileHash-MD5 23c2569a65870a9e412d98d5b3bdc554 2025-09-03
FileHash-MD5 33c9a47debdb07824c6c51e13740bdfe 2025-09-03
FileHash-MD5 435c7b4fd5e1eaafcb5826a7e7c16a83 2025-09-03
FileHash-MD5 451c23709ecd5a8461ad060f6346930c 2025-09-03
FileHash-MD5 6f2f61783a4a59449db4ba37211fa331 2025-09-03
FileHash-MD5 75a46b23825ce7aa4ca297d93450f4e2 2025-09-03
FileHash-MD5 7cc55f3cc2740e8818648efbec21615f 2025-09-03
FileHash-MD5 893fed20a939e613f2b108096573eb8b 2025-09-03
FileHash-MD5 d3ee425502cb60db1e75ef5bfd232c72 2025-09-03