COPPERHEDGE is a Lazarus-linked malware family/variant in the broader Manuscrypt cluster, publicly named by US-CERT/CISA in 2020. It is described as a full-featured remote access trojan/backdoor used with high confidence by North Korean HIDDEN COBRA/Lazarus operators to maintain persistence, conduct internal reconnaissance, execute arbitrary commands, and exfiltrate data. Multiple sources in the content explicitly characterize COPPERHEDGE as a Manuscrypt variant and note its use as an additional backdoor in Lazarus operations.
High-confidence reporting in the content shows COPPERHEDGE primarily as a Windows DLL implant, with DHS/FBI/DoD documenting 22 submitted samples and six variants labeled A through F. Across those variants, the malware uses HTTP-based beaconing and C2 with differing formats and encodings, including RC4-encrypted datagrams, custom encryption/obfuscation, Google-Analytics-like cookies, Base64-encoded POST parameters, and multipart POST fields such as "_webident_f" and "_webident_s". Hard-coded beacon strings mentioned in the content include "*dJU!*JE&!M@UNQ@" and "t34kjfdla45l." The government reporting cited in the content associates COPPERHEDGE with numerous C2 domains and provides sample hashes, YARA rules, and Snort detections.
Behaviorally, the content attributes to Manuscrypt/COPPERHEDGE the ability to run arbitrary commands, perform system reconnaissance, collect system information, download additional payloads, and exfiltrate data. In Operation SyncHole, COPPERHEDGE was specifically described as being used for internal reconnaissance, with configuration stored in an NTFS alternate data stream at %appdata%\Microsoft\Internet Explorer\brndlog.txt:loginfo. Kaspersky reporting in the content also notes use of an updated COPPERHEDGE as an additional backdoor in a complex Lazarus infection chain, and tradecraft overlaps such as DLL sideloading via Windows services and custom cryptography consistent with SIGNBT, LightlessCan, and COPPERHEDGE.
The malware is strongly associated in the content with Lazarus/HIDDEN COBRA/BlueNoroff activity, including financially motivated operations against cryptocurrency exchanges and related entities. Broader Manuscrypt reporting in the content also links the family to targeting governments, diplomatic entities, financial institutions, military and defense contractors, cryptocurrency platforms, IT and telecommunications operators, gaming companies, media outlets, casinos, universities, and security researchers. Specific campaign context in the content includes TraderTraitor-style cryptocurrency targeting and South Korea-focused Operation SyncHole, where Lazarus used watering-hole attacks and exploitation of Cross EX and Innorix Agent-related weaknesses alongside ThreatNeedle, wAgent, Agamemnon, SIGNBT, and COPPERHEDGE.
Notable indicators directly mentioned in the content include sample SHA-256 hashes such as d8af45210bf931bc5b03215ed30fb731e067e91f25eda02a404bd55169e3e3c3, 7985af0a87780d27dc52c4f73c38de44e5ad477cb78b2e8e89708168fbc4a882, e98991cdd9ddd30adf490673c67a4f8241993f26810da09b52d8748c6160a292, c2f150dbe9a8efb72dc46416ca29acdbae6fd4a2af16b27f153eaabd4772a2a1, 37bb27f4eb40b8947e184afddba019001c12f97588e7f596ab6bc07f7c152602, e6fc788b5ff7436da4450191a003966a68e2a1913c83f1d3aec78c65f3ba85ca, 284bc471647f951c79e3e333b2b19aa37f84cc39b55441a82e2a5f7319131fac, a1cdb784100906d0ac895297c5a0959ab21a9fb39c687baf176324ee84095472, b4bf6322c67a23553d5a9af6fcd9510eb613ffac963a21e32a9ced83132a09ba, 134b082b418129ffa390fbee1568bd9510c54bfdd0e6b1f36bc7b8f867e56283, 0a763da26a67cb2b09a3ae6e1ac07828065eb980e452ce7d3354347976038e7e, 1884ddc53ef66488ca8fc641b438895fcaada77c15210118465377c63223b3bc, and c24c322f4535def3f8d1579c39f2f9e323787d15b96e2ee457c38925effe2d39; C2 domains including 530hr.com, 028xmz.com, 168wangpi.com, marmarademo.com, 33cow.com, 97nb.net, anlway.com, apshenyihl.com, ap8898.com, aloe-china.com, 92myhw.com, aisou123.com, markcoprintandcopy.com, aedlifepower.com, 919xy.com, pakteb.com, nuokejs.com, qdbazaar.com, aurumgroup.co.id, 51shousheng.com, new.titanik.fr, duratransgroup.com, eygingenieros.com, eventum.cwsdev3.biz, theinspectionconsultant.com, danagloverinteriors.com, as-brant.ru, rxrenew.us, creativefishstudio.com, sensationalsecrets.com, rhythm86.com, cabba-cacao.com, 3x-tv.com, castorbyg.dk, matthias-dlugi.de, locphuland.com, streamf.ru, vinhsake.com, bogorcenter.com, stokeinvestor.com, growthincone.com, and inverstingpurpose.com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Google released an update and thanked us for discovering this attack... CVE-2024-4947... The exploit contains code for two vulnerabilities: the first is used to gain the ability to read and write Chrome process memory from the JavaScript... CVE-2024-4947 ... is the vulnerability in this new compiler. | We closely monitor their activities and quite often see them using their signature malware in their attacks — a full-feature backdoor called Manuscrypt.
"APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析" published by Qihoo360. | "APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析"
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We closely monitor their activities and quite often see them using their signature malware in their attacks — a full-feature backdoor called Manuscrypt.
We closely monitor their activities and quite often see them using their signature malware in their attacks — a full-feature backdoor called Manuscrypt.
Listed in the Wiz “TraderTraitor: Deep Dive” entry alongside GolangGhost and other tooling.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Under the hood, this website had a hidden script that ran in the user’s Google Chrome browser, launching a zero-day exploit and giving the attackers complete control over the victim’s PC. Visiting the website was all it took to get infected.
Simply clicking a link on a social network or in an email can lead to the complete compromise of a personal computer or corporate network... The attackers’ activity was not limited to X — they also used professionally designed websites with additional malware, premium accounts on LinkedIn, and spear phishing through email.
The response is written to disk and executed in a new shell using the child_process.exec() method in Node.js.
The decrypted data is written as a file to the system’s temporary directory... and executed using the child_process.exec() method of Node.js, which spawns a shell as a child process of the current Electron application.
We discovered that prior to the detection of Manuscrypt, our technologies also detected exploitation of the Google Chrome web browser originating from the website detankzone[.]com... the exploit contains code for two vulnerabilities: the first is used to gain the ability to read and write Chrome process memory from the JavaScript, and the second is used to bypass the recently introduced V8 sandbox.
The malicious website attacking its visitors using a Google Chrome zero-day was inviting them to download and try a beta version of a computer game... We downloaded detankzone.zip and it looked legit: the 400 MB-archive contained a valid file structure of a game developed in Unity.
At this point, the attackers need additional vulnerabilities to escape the Chrome process and gain full access to the system. In the best practices of sophisticated attackers, they run a validator in the form of a shellcode... to decide whether to provide the next stage (another exploit) or not.
Variant A uses RC4 encryption to obfuscate import loading... Variant B datagrams are RC4 encrypted... Variant D ... Datagrams are encrypted with a combination of RC4 and differential XOR... Variant E ... Base64 encoded data... Variant F ... Datagrams are encoded using a single byte XOR with the value "0xAA".
9e4bd9676bb3460be68ba4559a824940a393bde7613850eda9196259e453b9f3 ... Ikarus Trojan.Win64.Themida
Variant A uses RC4 encryption to obfuscate import loading... Variant B performs the same RC4 key as variant A for Application Programming Interface (API) obfuscation... Variant C performs API loading at runtime but does not obfuscate the strings.
"...gather basic system information (T1082, T1083, T1057, T1049, T1016, T1087.001)..."
"...gather basic system information (T1082, T1083, T1057, T1049, T1016, T1087.001)..."
"...gather basic system information (T1082, T1083, T1057, T1049, T1016, T1087.001)..."
Manuscrypt is a full-featured Remote Access Tool (RAT) capable of running arbitrary commands, performing system reconnaissance, and exfiltrating data.
"...gather basic system information (T1082, T1083, T1057, T1049, T1016, T1087.001)..."
"...gather basic system information (T1082, T1083, T1057, T1049, T1016, T1087.001)..."
This variant also obfuscates Hypertext Transfer Protocol (HTTP) header strings using a custom character manipulation where the certain ranges of characters are modified by either adding or subtracting a constant value 9.
The update function makes an HTTP POST request to a PHP script hosted on the TraderTraitor project’s domain at either the endpoint /update/ or /oath/checkupdate.php.
Variant A will generate HTTP POST requests with the following format... POST /<uri> HTTP/1.1 ... Content-Type: multipart/form-data ... Host: <domain> ... Variant B generates an HTTP POST request similar to Variant A... Variant C ... use of a generated cookie to pass certain information instead of multi-part HTTP POST requests... Variant E ... uses a single HTTP POST body with four parameters of Base64 encoded data... Variant F ... uses multi-part HTTP POST messages consisting of three parts holding the victim id, response code, and datagram.
FBI has high confidence that HIDDEN COBRA actors are using malware variants in conjunction with proxy servers to maintain a presence on victim networks and to further network exploitation.
317 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
"APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析"
A named malware family referenced in TraderTraitor-related reporting alongside other DPRK malware.
Referenced as a Lazarus malware/tool family associated with custom cryptography and deployment patterns similar to the analyzed loader.
COPPERHEDGE is referenced as a Lazarus-associated malware/tool family with similar DLL sideloading via Windows service behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.