Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE
Three separate pieces of cross-platform malware, PondRAT, ThemeForestRAT, and RemotePE, are distributed through a social engineering effort that has been linked to the Lazarus Group, a threat actor with ties to North Korea.
An employee's system was compromised as a result of the 2024 attack, which was seen by NCC Group's Fox-IT and targeted a company in the decentralized finance (DeFi) industry.
According to Yun Zheng Hu and Mick Koomen, the actor then carried out discovery from within the network by utilizing several RATs in conjunction with additional tools, such as to harvest credentials or proxy connections. The actor then switched to a more covert RAT, which probably indicated the attack's next phase.
The threat actor starts the attack chain by posing as an actual employee o...


