PowerRatankba is a PowerShell-based Lazarus-linked malware implant closely related to the earlier Ratankba family and used in financially motivated intrusion campaigns, particularly those targeting cryptocurrency users and organizations. It has been associated with Lazarus subclusters including BlueNorOff and APT38, and has also been observed in connection with the TrickBot-derived Anchor framework, indicating use in broader post-exploitation workflows.
PowerRatankba primarily functions as an initial-stage reconnaissance implant and stager. It collects host profiling data such as system identity, network information, operating system timing and locale details, selected port status, and running processes, then reports to command infrastructure for victim triage. On selected systems it can download and execute additional payloads, including more capable remote-access tooling such as a custom Gh0st RAT variant. Reported command support includes remote command execution, payload retrieval and execution, and in some variants payload injection.
Persistence mechanisms reported for PowerRatankba include Startup-folder execution for lower-privilege contexts and scheduled tasks or other autostart methods depending on privileges. In some campaign reporting, a related variant acted as a PowerShell reverse shell backdoor with command execution over HTTPS and persistence via user-logon autostart or service creation. The malware has been used to enable follow-on credential theft and remote control of systems of interest, especially in cryptocurrency-focused operations.
Observed delivery methods are diverse and heavily social-engineering driven. Campaigns have used spearphishing and lure-based delivery through malicious shortcut files, compiled HTML help files, JavaScript downloaders, macro-enabled Office documents, fake software updates, and trojanized cryptocurrency applications distributed via impersonation sites. Recruitment-themed social engineering has also been reported in enterprise targeting. The malware targets Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool, an Evolved RATANKBA, and More PowerRatankba
The attack campaign was active in December 2018, have used PowerRatankba, a PowerShell-based malware variant that closely resembles the original Ratankba implant.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Several large email phishing campaigns attempted to trick unsuspecting victims into visiting fake webpages to download or update cryptocurrency applications. The copycat websites were mirror images of legitimate websites... The only exception was the link to download the Windows version of the application, which was hosted on the copycat websites.
Most recently, several large email phishing campaigns attempted to trick unsuspecting victims into visiting fake webpages to download or update cryptocurrency applications.
Threat vectors for this new toolset, dubbed PowerRatankba, include highly targeted spearphishing campaigns using links and attachments... The campaigns discussed in this research began on or around June 30th, 2017. According to our data those campaigns were highly targeted spearphishing attacks targeting at least one executive at a cryptocurrency organization
PowerSpritz has been observed being delivered via spearphishing attacks using the TinyCC link shortener service to redirect to likely attacker-controlled servers hosting the malicious PowerSpritz payload.
The attackers delivered the malware, according to Flashpoint a trusted Redbanc IT professional clicked to apply to a job opening found on social media... The person that published the job opening then contacted the employee via linkedin Skype, etc for an interview and tricked him into installing the malicious code.
If the user account does have administrator privileges then PowerRatankba will download a PowerShell script... and finally create a scheduled task to execute the downloaded PowerShell script on system startup.
When a command is received, it is executed using the PowerShell command in Windows. The output of the command is captured and sent back to the C2 server.
PowerSpritz... decrypts a PowerShell command that downloads the first stage of PowerRatankba... The second method downloads a similar VBScript-based PowerRatankba downloader using PowerShell directly in the CHM
The command cmd executes command using 'cmd.exe /c $cmdInst'.
The first method uses a VBScript Execute command and BITSAdmin tool to download a malicious VBScript file... Once the downloaded VBScript is executed, it will attempt to download PowerRatankba
Throughout November several compressed ZIP files containing a JavaScript (JS) downloader were observed... First, an obfuscated PowerRatankba.B PowerShell script is downloaded from a fake image URL
The first method uses a VBScript Execute command and BITSAdmin tool to download a malicious VBScript file.
If the user account does have administrator privileges then PowerRatankba will download a PowerShell script... and finally create a scheduled task to execute the downloaded PowerShell script on system startup.
The first method uses a VBScript Execute command and BITSAdmin tool to download a malicious VBScript file.
This latter code is registered as a service through the “sc create” command as, the malware gain persistence by setting an autostart.
PowerRatankba.A saves a JS file to the victim’s Startup folder as appView.js... If the user account does not have administrator privileges then a VBScript file is downloaded... and saved to the executing user’s Startup folder... RatankbaPOS... sets up persistence by creating a registry key in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\igfxgpttray.
If the user account does have administrator privileges then PowerRatankba will download a PowerShell script... and finally create a scheduled task to execute the downloaded PowerShell script on system startup.
Download payload from provided URL and execute via memory injection... inject into process memory using Invoke-ReflectivePEInjection... RatankbaPOS will be written to disk as c:\windows\temp\hkp.dll and the PID of xplatform.exe process will be used to inject hkp.dll into xplatform.exe using LoadLibraryA and CreateRemoteThread
This latter code is registered as a service through the “sc create” command as, the malware gain persistence by setting an autostart.
PowerRatankba.A saves a JS file to the victim’s Startup folder as appView.js... If the user account does not have administrator privileges then a VBScript file is downloaded... and saved to the executing user’s Startup folder... RatankbaPOS... sets up persistence by creating a registry key in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\igfxgpttray.
The dropper downloads and executes PowerRatankba in the background by useing (Base64)... The program contains Base64-encoded data, which is often used to hide malicious commands from antivirus and security software.
A LNK masquerading as a PDF document was discovered... The malicious 'Scanned Document Part 1.pdf.lnk' LNK file, along with a corrupted PDF named 'Scanned Document Part 2.pdf,' were compressed in a ZIP file named 'Scanned Documents.zip'.
Download payload from provided URL and execute via memory injection... inject into process memory using Invoke-ReflectivePEInjection... RatankbaPOS will be written to disk as c:\windows\temp\hkp.dll and the PID of xplatform.exe process will be used to inject hkp.dll into xplatform.exe using LoadLibraryA and CreateRemoteThread
PowerRatankba first sends detailed information about the infected device... including the computer name, IP address(es)... if ports 139, 3389, and/or 445 are open/closed/filtered
95 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell-based backdoor/reverse shell used to gain remote access, execute attacker commands, send command output to a C2 server over HTTPS, and maintain persistence via service creation and Windows autostart/registry mechanisms.
Remote access tool previously linked to North Korean activity and described here as being used within the Anchor framework.
Remote access malware associated with BlueNorOff operations.
Evolved RAT used in Lazarus campaigns targeting cryptocurrencies and banks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.