TAINTEDSCRIBE is a Windows Trojan associated with North Korean government-linked HIDDEN COBRA activity. It functions as a beaconing implant that establishes persistence, communicates with command-and-control infrastructure using obfuscated network traffic, and retrieves an additional command-processing module to extend functionality. The malware has been disguised as Microsoft Narrator to reduce suspicion and has been observed persisting by copying itself into the current user's Startup folder.
TAINTEDSCRIBE supports host reconnaissance and post-compromise tasking. Documented capabilities include process discovery, target system enumeration, local time discovery, file deletion, file execution, process creation and termination, and enabling Windows command-line access. It can also collect files, compress them, and transmit them to command-and-control infrastructure, indicating an exfiltration role. The malware has been observed changing file timestamps, consistent with defense-evasion and anti-forensics behavior.
Its command-and-control design emphasizes resilience and concealment. TAINTEDSCRIBE can randomly select from multiple hard-coded callback addresses and retry alternate infrastructure if a connection attempt fails. For communications, it uses a FakeTLS-style session authentication scheme and subsequently wraps traffic in a TLS-like structure with payload data encrypted using a Linear Feedback Shift Register algorithm. This combination is intended to make malicious traffic resemble legitimate encrypted sessions while frustrating straightforward inspection.
TAINTEDSCRIBE has been publicly identified by U.S. government agencies as a malware variant used by the North Korean government. It has been described as a downloader and launcher with LFSR-based communications support, and it appears in the broader Lazarus or HIDDEN COBRA malware ecosystem alongside other DPRK-attributed implants used to maintain access and support further exploitation of victim networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The reports outline three different malware types: PebbleDash Trojan, TaintedScribe Trojan and CopperHedge RAT.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The two Trojans, PebbleDash and TaintedScribe are beaconing implants that can be used to exfiltrate information, download additional malicious content and execute commands on infected devices. CopperHedge is a variant of the Manuscrypt RAT and is a remote access tool that can be used to run arbitrary commands...
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Once the FakeTLS handshake is complete, all further packets use a FakeTLS header, followed by LFSR encrypted data.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
"AppleSeed has compressed collected data before exfiltration."; "APT28 used a publicly available tool to gather and compress multiple documents..."; "Aria-body has used ZIP to compress data..."; "Cadelspy...compress stolen data into a .cab file."; "Daserf hides collected data in password-protected .rar archives."; "FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration."; "Lazarus Group has compressed exfiltrated data with RAR...archive specified directories in .zip format"; "XCSSET will compress entire ~/Desktop folders..."
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The malware utilizes a “FakeTLS” scheme in an attempt to obfuscate its network communications. It picks a random URL from a list to use in the TLS certificate. The sample and the C2 externally appear to perform a standard TLS authentication... | This report looks at a full-featured beaconing implant... These samples uses FakeTLS for session authentication and for network encryption utilizing a Linear Feedback Shift Register (LFSR) algorithm.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that can change timestamps of specified files.
Malware that persists by copying itself into the user's Startup folder under a deceptive filename.
Malware that rotates among multiple hard-coded C2 IP addresses when communication fails.
Backdoor that uses an LFSR-based algorithm for network encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.