Andariel’s “Jupiter” malware and the case of the curious C2

2023-05-16 DCSO

https://medium.com/@DCSO_CyTec/andariels-jupiter-malware-and-the-case-of-the-curious-c2-dbfe29f57499

Thumbnail for Andariel’s “Jupiter” malware and the case of the curious C2

DCSO describes “Jupiter,” a previously little-documented PureBasic malware family it attributes to Andariel, a North Korean Lazarus subgroup. The malware has appeared sporadically since 2020, including an OSPREY-signed sample tied to an attempted attack on a German medical or pharmaceutical company and a sample later referenced in CISA’s H0lygh0st ransomware advisory. A fresh 2023 sample contained C2 configuration suggesting possible abuse of India’s National Institute of Virology web presence, although DCSO could not prove the server was actively compromised. Jupiter provides basic download and shell-command execution functions, with command output returned to C2, and the targeting context aligns with DPRK interest in healthcare and medical research during and after the COVID-19 pandemic.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c28bb61de4a6ad1c5e225ad9ec2eaf4… 2023-05-16 2024-07-25
HASH 34d5a5d8bec893519f204b573c33d54… 2023-05-16 2024-07-25
HASH aa29bf4292b68d197f4d8ca026b97ec… 2023-05-16 2024-07-25
HASH 772b06f34facf6a2ce351b8679ff957… 2023-05-16 2024-07-25
HASH 9a5504dcfb7e664259bfa58c46cfd33… 2023-05-16 2024-07-25
HASH 664f8d19af3400a325998b332343a93… 2023-05-16 2024-07-25
IPv4 40.121.90.194 2022-09-08 2023-09-12
URL http://projectcell.niv.co.in/no… 2023-05-16 2023-05-16
URL http://sora.bz/xoops_root_path/… 2023-05-16 2023-05-16
URL http://sora.bz/xoops_root_path/… 2023-05-16 2023-05-16
URL http://eflow.co.kr/member_image… 2023-05-16 2023-05-16
DOMAIN niv.co 2023-05-16 2023-05-16
DOMAIN ns.iknowledgefactory.com 2023-05-16 2023-05-16
DOMAIN projectcell.niv.co 2023-05-16 2023-05-16
DOMAIN eflow.co.kr 2023-05-16 2023-05-16
DOMAIN projectcell.niv.co.in 2023-05-16 2023-05-16
DOMAIN sora.bz 2023-05-16 2023-05-16
DOMAIN niv.icmr.org 2023-05-16 2023-05-16
IPv4 103.73.189.76 2023-05-16 2023-05-16
IPv4 3.89.226.234 2023-05-16 2023-05-16
IPv4 173.249.44.87 2023-05-16 2023-05-16
IPv4 173.249.33.80 2023-05-16 2023-05-16

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back