Rising Sun is a modular Windows backdoor associated with Lazarus Group activity and observed as a payload delivered by the Sharpshooter campaign. It is designed for post-compromise reconnaissance, command-and-control communications, and host manipulation. Documented capabilities include enumerating running processes, collecting username information, identifying operating system details, and gathering network adapter and IP configuration data from infected hosts. Rising Sun can transmit collected information to its command-and-control infrastructure using HTTP POST requests, and some variants support SSL to protect command-and-control traffic.
The malware also includes defense-evasion and operational support features. It can modify file attributes to hide artifacts, delete files on operator command, and use dynamic API resolution through standard Windows loading functions to reduce static visibility. Samples have used simple XOR-based self-decryption and runtime configuration decryption to conceal code and embedded settings. Rising Sun has also been observed querying Windows system information from the Registry to identify the host operating system.
Rising Sun is notable for code overlap with other Lazarus-linked implants, including shared HTTP wrapper functionality seen in CRAT and Wild Positron, reinforcing its placement within a broader Lazarus malware ecosystem. Its use in targeted intrusion activity against sectors including nuclear, defense, energy, and financial services indicates an espionage-oriented role as a flexible backdoor for victim profiling and data collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sharpshooter's first-stage downloader installed Rising Sun to the startup folder %Startup%\mssync.exe .
Code Reuse - CRAT uses the same HTTP wrapper library used by other Lazarus implants such as Wild Positron and Rising Sun.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that can detect the username of the infected host.
Detects network adapter and IP address information.
Modular backdoor malware used to exfiltrate collected data over HTTP POST to a C2 server.
Detects the username of the infected host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.