RP_Proxy is a custom proxying utility observed in Lazarus Group (North Korea state-backed) intrusion activity associated with Medusa ransomware extortion campaigns. Reporting describes RP_Proxy as being used to route malicious traffic (including routing traffic internally) to support attacker operations and to move/exfiltrate stolen information with reduced visibility, alongside other tooling such as Comebacker, BLINDINGCAN, ChromeStealer, Infohook, Mimikatz, and Curl. The activity discussed includes targeting of U.S. healthcare and non-profit organizations and at least one Middle East entity, with attribution broadly to Lazarus/Stonefly (Andariel) but with caveats that not all Medusa incidents are necessarily attributable to North Korean operators. The provided content does not include specific RP_Proxy file hashes, filenames, or protocol-level details beyond its role as a custom proxy tool in these campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Tools Used In Recent Campaigns... RP_Proxy custom proxy tool"
"Tools Used In Recent Campaigns... RP_Proxy custom proxy tool"
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Internal traffic routing/proxy tool used to move stolen information and reduce detection during intrusions.
Custom proxying utility used to route attacker traffic through compromised environments.
Custom proxy tool used to route traffic and support command-and-control/operational connectivity during intrusions.
Custom proxy tool used to route traffic/enable pivoting during intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.