Rising Sun

Malware updated 4 months ago (2024-05-05T01:18:01.502Z)
Download STIX
Preview STIX
Rising Sun is a malicious software (malware) that shares significant similarities with the Lazarus Group’s Duuzer implant. It uses source code from the Duuzer backdoor, a malware first used in a 2015 campaign that targeted South Korean organizations, primarily in manufacturing. The Rising Sun malware was observed in attacks prior to the discovery of 'Sharpshooter' and shares the tactics, techniques, and procedures (TTPs) seen in operations attributed to the Lazarus group. Researchers have noted that all Rising Sun implants were based on the original Backdoor Duuzer source code. This malware operates as a second-stage implant, performing reconnaissance on the victim's network. Its main function is to gather and encrypt data from the victim, including the victim devices’ computer name, IP address data, native system information, and more. This fully modular backdoor has been used in various cyberattacks since at least 2016, according to researchers Ryan Sherstobitoff and Asheer Malhotra from McAfee, along with the company's Advanced Threat Research Team (ATR). The connection between Rising Sun and Lazarus group is further reinforced by their similar methods of operation. Both groups have used fake job recruitment campaigns to disguise their attacks. Moreover, Lazarus relied on similar versions of Rising Sun in activity tracked in 2017. These factors point to a strong link between the two adversaries, suggesting a shared origin or collaboration in their malicious activities.
Description last updated: 2024-05-05T01:12:00.312Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Rising Sun Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
Op 'Sharpshooter' Connected to North Korea's Lazarus Group
MITRE
2 years ago
RSAC 2019: New Operation Sharpshooter Data Reveals Higher Complexity, Scope | Threatpost