Escad is a backdoor malware identified as a Destover variant linked to the 2014 Sony Pictures attack and later referenced in McAfee’s analysis of the Lazarus Group/Hidden Cobra campaign Operation GhostSecret. The reporting ties Escad to Hidden Cobra/Lazarus through shared code and infrastructure, including identical PE rich-header signatures between a 2014 Backdoor.Escad sample and a February 2018 Destover-like implant, reuse of FakeTLS with PolarSSL over port 443 for command-and-control, and SSL certificate and hosting overlaps with infrastructure associated with the Sony intrusion. In the cited reporting, Escad is described as a backdoor used alongside other Lazarus tooling such as Bankshot and Proxysvc.
High-confidence capabilities described for the related Destover-like/Escad-linked implant include system reconnaissance, directory listing, file read/write operations, process creation and enumeration, file wiping and deletion, storing encoded data in the registry, command execution, and data exfiltration to its control server over port 443. The malware was associated with campaigns targeting organizations across critical infrastructure, entertainment, finance, healthcare, telecommunications, and higher education, with activity observed across at least 17 countries in March 2018. The broader activity was attributed with high confidence to Hidden Cobra, also known as Lazarus Group.
Reported indicators directly associated with Escad-linked analysis include the 2014 Backdoor.Escad sample hash 8a7621dba2e88e32c02fe0889d2796a0c7cb5144; related Destover-like sample hashes fe887fcab66d7d7f79f05e0266c0649f0114ba7c and 8f2918c721511536d8c72144eabaf685ddc21a35; command-and-control IPs 203.131.222.83, 14.140.116.172, and 203.131.222.109; and SSL certificate fingerprint d0cb9b2d4809575e1bc1f4657e0eb56f307c7a76.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers behind Operation GhostSecret used a similar infrastructure to earlier threats, including SSL certificates used by FakeTLS in implants found in the Destover backdoor variant known as Escad, which was used in the Sony Pictures attack.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used in Operation GhostSecret attributed to Lazarus Group, enabling remote access and ongoing control of compromised systems to support reconnaissance and data theft.
Destover backdoor variant used in the 2014 Sony Pictures attack; used FakeTLS/PolarSSL-like infrastructure and is compared against newer Destover-like implants for code/protocol similarity.
A Destover backdoor variant associated with Hidden Cobra and the Sony Pictures attack, notable here for its FakeTLS communications and code/development overlap with newer implants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.