BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Lazarus Group Targets DeFi Firm with Trio of Advanced RAT Malware

Lazarus Group Targets DeFi Firm in 2024 Cyberattack Using Fake Scheduling Sites, Chrome Zero-Day, and Advanced Malware

  • North Korean Hacker group Lazarus ran a 2024 cyber campaign targeting a decentralized finance company.
  • The attackers used social engineering to deliver cross-platform Malware called PondRAT, ThemeForestRAT, and RemotePE.
  • Initial contact happened via fake trading company accounts and scam scheduling websites imitating Calendly and Picktime.
  • The attack led to credential theft, system discovery, and installation of different Remote Access Trojans (RATs).
  • The campaign likely used a Chrome browser zero-day exploit to gain initial entry before switching to more advanced tools.

A cyberattack campaign by the North Korea-linked group Lazarus was detected in 2024, with Hackers targeting an employee of a decentralized finance (DeFi) organization. The incident involved the distribution of three different types of malware—PondRAT, ThemeForestRAT, and RemotePE—to compromise company networks.

- Advertisement -

Researchers at NCC Group’s Fox-IT reported that the hackers started by impersonating a trading company employee on Telegram. They then used fake websites that looked like popular scheduling tools to engage the victim and arrange a meeting. After gaining access to the system, the attackers deployed a loader named PerfhLoader, which installed a simplified form of existing malware known as PondRAT.

“From there, the actor performed discovery from inside the network using different RATs in combination with other tools, for example, to harvest credentials or proxy connections,” said Fox-IT’s Yun Zheng Hu and Mick Koomen. The hackers continued the attack by switching from PondRAT to ThemeForestRAT, and later cleaned up after themselves and installed a more sophisticated tool called RemotePE.

Fox-IT stated that the initial access point is not fully confirmed, but there is some evidence that a then-unknown Chrome browser vulnerability was used. Alongside PondRAT, the attackers installed additional tools such as a keylogger, screenshot utility, Chrome credential and cookie stealer, and proxies including MidProxy and Proxy Mini. Tools like Mimikatz, used to collect passwords, were also found.

The malware programs enabled functions like monitoring for new remote desktop sessions, running shell commands, managing files, and launching further attacks or hiding activity. Fox-IT noted that Cybersecurity-advisories/aa21-048a” target=”_blank” rel=”noopener”>PondRAT has been active since at least 2021, and ThemeForestRAT displays similarities to malware used in the 2014 Sony Pictures Entertainment attack.

- Advertisement -

RemotePE, written in C++, is a more advanced remote access tool delivered via a chain of loaders and is likely intended for high-value targets.

Fox-IT describes the approach as moving from basic tools like PondRAT for initial compromise, then upgrading to more complex malware for broader control, all while minimizing detection.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Backlash forces Pump Fun, Kraken to delete Biden coin posts

Pump Fun and Kraken deleted posts promoting Hunter Biden's $LAPTOP memecoin after community backlashThe...

Bitmine nears 5% Ether supply goal with $69.5M purchase

Bitmine Immersion Technologies acquired 28,086 ETH worth approximately $69.5 million, lifting total holdings to...

Adobe Patches Critical Magento Flaw Under Active Attack

Adobe patched CVE-2026-75650 (CVSS 10.0), a zero-day in Commerce and Magento Open Source exploited...

Polish court detains fifth suspect in Zondacrypto fraud case

A Polish court approved pretrial detention for Roman Ż., charged with computer fraud and...

Bitcoin-Gold Correlation Hits 6-Year High as Hedge Demand Rises

Bitcoin's correlation with Gold hits a six-year high, signaling its use as a hedge...

Must Read

Top 9 Most Legit Bitcoin Faucets

Bitcoin faucets are platforms where you can earn Bitcoin free. Some other faucet apps and websites allow users to receive different cryptocurrencies for free....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading