EarlyRAT is a lightweight HTTP-based remote access trojan associated with Andariel, a North Korea-linked Lazarus Group sub-cluster. It has been observed in mid-2022 intrusion activity following exploitation of Log4j/Log4Shell and was also found delivered through phishing documents that require users to enable macros, which then execute commands to drop the malware. Reporting also states that EarlyRAT is known as “Jupiter.”
The malware is described as previously undocumented, simple in design, and written in PureBasic. Its functionality is primarily limited to remote command execution. On startup, it collects system information and sends it to its command-and-control server. Its HTTP C2 traffic uses parameters including "id" and "query," and also supports "rep0" and "page." The "query" value is Base64-encoded and rolling-XOR encrypted, with the "id" parameter used as the key for decryption.
EarlyRAT was first noticed in a Log4j-related case where additional malware was downloaded after exploitation, and researchers later identified further samples delivered via phishing lures. One report notes that the VBA code used to deliver EarlyRAT pinged a server associated with the HolyGhost/Maui ransomware campaign. Additional reporting links EarlyRAT/Jupiter to later Lazarus tooling through a shared code-signing certificate artifact, and EarlyRAT was listed in a February 2023 CISA advisory concerning North Korean ransomware activity targeting healthcare and critical infrastructure worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Andariel has leveraged N-day flaws, including CVE-2021-44228 (Log4Shell) affecting VMware Horizon, as well as vulnerabilities in Apache Tomcat and on-premises Microsoft SharePoint servers.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"EarlyRat: Lightweight HTTP-based malware delivered via Log4j exploitation or phishing, using Base64 and rolling XOR in C2 parameters."
1 distinct technique documented for this family, organized by ATT&CK tactic.
"The group frequently targets unpatched, internet-facing systems. Vulnerability exploitation: Andariel has leveraged N-day flaws, including CVE-2021-44228 (Log4Shell) affecting VMware Horizon, as well as vulnerabilities in Apache Tomcat and on-premises Microsoft SharePoint servers."
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lightweight HTTP-based backdoor delivered via Log4j exploitation or phishing; uses Base64 and rolling XOR in C2 parameters.
PureBasic-based implant attributed to the Andariel subgroup; reported as deployed via exploitation of Log4j and listed by CISA in an advisory about North Korean ransomware activity affecting healthcare and critical infrastructure.
Simple RAT that collects system information and executes commands; C2 communications use parameters including an 'id' key and Base64 + rolling-XOR encoded 'query' content; delivered via phishing documents/macros and also observed in Log4j-related cases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.