Cur1Agent is a downloader associated with the North Korean financially motivated threat actor BlueNoroff/TA444. It was observed in late 2022 as part of evolving delivery chains that used disk image formats such as VHD and ISO, as well as earlier Word-document and ZIP/LNK-based intrusion methods, to evade Windows Mark-of-the-Web protections and deliver follow-on payloads. Its primary purpose is to fetch the next-stage malware.
The malware uses the cURL library for network communications and employs the distinctive user-agent string "cur1-agent." Researchers reported that it conditionally varied POST data, using "da" when Avira or Avast were present and otherwise "dl," to retrieve the next-stage payload. Depending on the variant, Cur1Agent could inject the fetched payload into explorer.exe or write it to %TEMPLATES%\marcoor.dll. In related chains, downloader components used RC4-encrypted configuration data, restored a URL from encrypted config, checked system memory to evade sandbox or VM environments, enumerated antivirus products including Sophos, Kaspersky, Avast, Avira, Bitdefender, TrendMicro, and Windows Defender, and performed ntdll unhooking when certain security products were present. A mutex named da9f0e7dc6c52044fa29bea5337b4792b8b873373ba99ad816d5c9f5f275f03f was also reported in this tooling cluster.
Observed infrastructure and delivery included a TA444 VHD serving Cur1Agent, with reporting noting the domain superiorexhbits[.]com was seen serving such a VHD. Related BlueNoroff infrastructure included domains impersonating venture capital firms and banks, especially Japanese entities, suggesting targeting interest in financial and blockchain-related organizations. Researchers assessed the final payload delivered by this chain was similar to a previously reported BlueNoroff backdoor referred to as "Persistence Backdoor #2."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“In fact, this same domain was observed serving a TA444 VHD containing Cur1Agent on the same day.”
1 distinct technique documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Payload delivered inside a VHD as part of TA444 activity; described as an ‘agent’ (backdoor-like implant) in the delivery chain.
Downloader used by BlueNoroff that leverages the cURL library to retrieve next-stage payloads, includes encrypted RC4 configuration/URL handling, performs environment/AV checks (including unhooking ntdll to evade EDR), and either writes a DLL payload to disk for execution via rundll32 or injects the fetched DLL into explorer.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.