He is everywhere
First seen: 2016-02 •
Last seen: 2026-06
#RatankbaPOS • 2017-12
Proofpoint described RatankbaPOS as part of financially motivated Lazarus Group activity centered on cryptocurrency and POS-related malware operations. The reporting connected RatankbaPOS with PowerRatankba downloaders, multiple delivery formats including shortcut, CHM, Office macro, and backdoored PyInstaller payloads, and related second-stage tooling such as PowerRatankba.B and Gh0st RAT, with attribution supported by shared encryption, obfuscation, functionality, decoys, code overlap, and C2 characteristics.
1
Related Reports
1
Affected Countries
102
Months Since
He is everywhere