Opencarrot

Malware updated 4 months ago (2024-05-04T21:18:29.661Z)
Download STIX
Preview STIX
OpenCarrot is a malicious software (malware) that targets Windows operating systems, enabling unauthorized access and control over infected machines. Identified by IBM XForce, it has been linked to the activities of the Lazarus Group, a North Korean cyber threat operation known for its sophisticated attacks. The malware supports a wide range of functionalities, including reconnaissance, file system and process manipulation, reconfiguration and connectivity commands, and monitoring of new USB drives for potential lateral movement within an infected network. It also features relatively long sleep time periods, a characteristic often seen among Lazarus Group malware. The malware was discovered in two instances of North Korea-related compromise of sensitive internal IT infrastructure within a Russian Defense Industrial Base (DIB) organization, NPO Mashinostoyeniya, a missile and satellite developer. The criminals infiltrated the defense firm's email server and deployed OpenCarrot, allowing them total takeover of the infected machines and coordination across the compromised network. SentinelOne, a cybersecurity company, attributes the hack of the mail server to the ScarCruft APT group, while linking the deployment of OpenCarrot backdoor to the Lazarus Group. Further investigation into a leaked NPO Mashinostroyeniya email indicated a cyber incident involving the deployment of a malicious DLL on their systems in May. This led to the discovery that the missile maker had been impacted by the OpenCarrot backdoor malware, as reported by SentinelLabs. The presence of the OpenCarrot Windows OS backdoor was noted by researchers during their analysis, highlighting the continued threat posed by this malware and its associated threat groups.
Description last updated: 2024-05-04T21:05:53.565Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Windows
Backdoor
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
IDTypeVotesProfile Description
ScarCruftUnspecified
2
ScarCruft, also known as APT37, Inky Squid, RedEyes, Reaper, or Group123, is a North Korean threat actor group associated with malicious cyber activities. Their actions have been linked to the execution of targeted attacks against individual Android devices, as outlined in a VB2023 paper titled "Int
Source Document References
Information about the Opencarrot Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
Microsoft: North Korean hackers target Russian govt, defense orgs
CERT-EU
a year ago
FBI: DPRK cyber crooks may try to cash out $40m in crypto
Checkpoint
a year ago
14th August – Threat Intelligence Report - Check Point Research
Securityaffairs
a year ago
North Korea compromised Russian missile engineering firm NPO Mashinostroyeniya
CERT-EU
a year ago
North Korean Hackers Targeted Russian Missile Developer
CERT-EU
a year ago
Russian missile manufacturer subjected to North Korean APT attack
CERT-EU
a year ago
Elite North Korean Hackers Breach Russian Missile Developer
CERT-EU
a year ago
Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company
CERT-EU
a year ago
DPRK hackers had access to Russian missile maker system
CERT-EU
a year ago
Comrades in arms ? North Korea compromises... – Global Security Mag Online
CERT-EU
a year ago
Elite North Korean Hackers Breach Russian Missile Developer | IT Security News
CERT-EU
a year ago
North Korean cyber spies hacked sanctioned Russian missile engineering firm
CERT-EU
a year ago
Russian Missile Manufacturer Breached By North Korean Hackers
CERT-EU
a year ago
North Korean Hackers Compromise Russian Missile Maker
CERT-EU
a year ago
North Korean Hackers Targets Russian Missile Engineering Firm