Manuscrypt is a Lazarus-associated remote access trojan used in long-running espionage and financially motivated intrusion campaigns. It is widely linked to North Korean threat activity, including operations tracked under Lazarus, Hidden Cobra, BlueNoroff, and TraderTraitor, and has been observed in campaigns targeting defense enterprises, cryptocurrency exchanges, decentralized-finance organizations, blockchain companies, and other high-value sectors. COPPERHEDGE is commonly described as a Manuscrypt variant or closely related backdoor within the same malware lineage.
Manuscrypt is a full-featured backdoor designed to give operators persistent remote control over compromised systems. Reported capabilities include arbitrary command execution, host and network reconnaissance, file transfer, process and file enumeration, process creation and termination, configuration updates, timestomping, secure deletion, and data exfiltration. In some campaigns, related variants also used reflective loading, in-memory execution, process injection, and anti-analysis or anti-forensic measures to reduce detection and preserve access.
The malware has been documented primarily on Windows, but Linux ELF variants have also been identified, and Android samples have been reported under the Manuscrypt name. Cross-platform development and code overlap between PE and ELF variants indicate sustained maintenance and adaptation by its operators. Manuscrypt has also shown technical relationships with other Lazarus malware clusters, including ThreatNeedle, CookieTime, and MATA.
Delivery has varied by campaign. Lazarus operators have used trojanized cryptocurrency and DeFi applications, fake job or recruiter lures, phishing, watering-hole activity, and browser-exploit-driven compromise to deploy Manuscrypt or closely related implants. In cryptocurrency-focused operations, the malware has been used to harvest system information, search for wallet material and credentials, and support theft of digital assets. In defense-sector intrusions, it has served as a post-compromise access tool for intelligence collection and follow-on exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Google released an update and thanked us for discovering this attack... CVE-2024-4947... The exploit contains code for two vulnerabilities: the first is used to gain the ability to read and write Chrome process memory from the JavaScript... CVE-2024-4947 ... is the vulnerability in this new compiler. | We closely monitor their activities and quite often see them using their signature malware in their attacks — a full-feature backdoor called Manuscrypt.
"APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析" published by Qihoo360. | "APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析"
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CopperHedge is a variant of the Manuscrypt RAT and is a remote access tool that can be used to run arbitrary commands, perform system reconnaissance, and exfiltrate data.
Malware COPPERHEDGE RAT associated with Lazarus, observed in TraderTraitor activity. | In this way, TraderTraitor apps delivered malware such as MANUSCRYPT (a remote access trojan) onto victims’ systems. MANUSCRYPT would then harvest system info, execute arbitrary commands, and ultimately seek out cryptocurrency wallet keys or credentials to enable theft of funds.
We closely monitor their activities and quite often see them using their signature malware in their attacks — a full-feature backdoor called Manuscrypt.
Listed in the Wiz “TraderTraitor: Deep Dive” entry alongside GolangGhost and other tooling.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
The two Trojans, PebbleDash and TaintedScribe are beaconing implants that can be used to exfiltrate information, download additional malicious content and execute commands on infected devices. CopperHedge is a variant of the Manuscrypt RAT and is a remote access tool that can be used to run arbitrary commands...
Shell commands use the shell path recorded in configuration and execute in the form /c "<command> > <temp file> 2>&1".
These malicious apps – built on JavaScript [T1059.007] and Node.js using the Electron framework
payloads delivered by the macros discussed in Operation Blockbuster Sequel ... malware used in the HiddenCobra threat group ... source code was reused between previously reported samples and the cluster of new samples
공격자는 워터링 홀 또는 스피어 피싱 등 다양한 방식으로 공격 대상의 악성 URL 접속을 유도한 후, 취약점을 익스플로잇하여 최종적으로 백도어 악성코드를 설치하였다.
the malware used in the attack loads its payload from the system registry and decrypts it. The payload’s location in the registry is unique for each infected system.
The ultimately executed malware communicates via HTTP/HTTPS... to perform remote command execution, file theft, shellcode execution, and process injection.
The C2 server could respond with an encrypted second stage payload (using AES-256 [T1027]) that the app would decrypt and execute
When the malware runs, it randomly generates dropped filenames and adds 60MiB ~ 80MiB of junk data.
Repeatedly reads hidden additional module data from two PNG file paths stored in configuration, decrypts it, and injects it into explorer.exe.
The identified malware commonly constructed a multi-stage loading chain that decrypts subsequent payloads using ChaCha20 or AES-128 algorithms...
Dropped files are created in C:\Windows\System32 ... names such as edgsvc.dll, gsosvc.dat resemble normal system files... the dropper itself uses the normal system process name smss.exe.
PNG hiding uses normal image files with real PNG signatures... image viewers open them normally.
The ultimately executed malware communicates via HTTP/HTTPS... to perform remote command execution, file theft, shellcode execution, and process injection.
During initialization, it deletes the registry value containing configuration data, reads loader and backdoor data into memory, and then deletes the loader and backdoor files.
On shutdown, the loader, backdoor, configuration data, and Security Packages entry are restored...
Collects ... IPv4 address of network adapters...
CopperHedge is a variant of the Manuscrypt RAT and is a remote access tool that can be used to run arbitrary commands, perform system reconnaissance, and exfiltrate data.
These domains and IPv4 addresses are used to generate crafted TLS sessions similarly to the 'fake TLS' communication mechanisms ... includes a legitimate domain name in its SNI field yet is sent to a command and control IPv4 address.
The configuration contains multiple C&C URLs... confirmed C&C server URLs are three, all domestic servers.
MITRE Tactic Technique & ID ... Command & Control Application Layer Protocol: Web Protocols (T1071.001) Malware uses HTTPS callbacks to C2 servers.
338 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage backdoor used in watering-hole attacks against South Korean targets. It is loaded reflectively in memory, stores encrypted configuration in the registry or NTFS ADS, communicates over HTTP/HTTPS with compromised South Korean web servers, and supports remote command execution, file theft, shellcode/PE execution, process injection, persistence via service hijacking and SSP registration, and self-protection by deleting/restoring artifacts.
Backdoor deployed in the campaign that supports remote command execution, file theft, internal reconnaissance, process injection, and delivery of additional payloads. One described infection chain decrypted later stages in memory, injected code into svchost.exe, and read command-and-control information from the Windows registry.
Named malware/tool referenced in the context of a watering hole attack technical analysis report.
A backdoor executed reflectively from memory by the loader. It stores encrypted configuration in the registry or NTFS ADS depending on mode, establishes persistence via service hijacking and SSP registration, collects host information, communicates with multiple C2 URLs using ChaCha20/XOR/Base64-protected POST traffic, supports command execution, and can decrypt and inject additional modules into explorer.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.