BISTROMATH is a Windows remote access trojan associated with North Korean government cyber operations tracked by the U.S. government as HIDDEN COBRA and widely linked to Lazarus activity. It comprises full-featured implant variants together with a companion GUI builder/controller known as CAgent11 or Cyber Agent v11.0, which can manage compromised hosts and generate customized payloads.
BISTROMATH provides broad post-compromise control and surveillance capabilities. Documented functions include system reconnaissance, collection of host metadata, file upload and download, process and command execution, service and drive enumeration, reverse shell access, screen monitoring or remote desktop viewing, microphone capture, clipboard monitoring, keylogging, browser activity collection, cached password collection, and DLL load or unload support. The implants transmit victim profiling data such as system architecture, operating system details, language, country, user and host identifiers, and available drives.
The malware is delivered through trojanized Windows executables that decode an embedded fake bitmap into configuration data and shellcode, which then loads an embedded implant or can retrieve a payload from a configured remote location. Communications use simple XOR-based encoding. BISTROMATH includes multiple anti-analysis features, including checks for virtualized and sandboxed environments such as VMware, VirtualBox, QEMU, Bochs, Wine, and Sandboxie, as well as anti-debugging logic using standard debugger-detection APIs.
For persistence and stealth, BISTROMATH supports autorun mechanisms through startup entries and scheduled execution, and it can perform process hollowing. Reported variants also support DLL hijacking via a legitimate Windows utility. The associated controller can dynamically build implants with configurable callback settings and beacon timing, indicating an operator-oriented framework intended for long-term access, host management, surveillance, and data theft on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BISTROMATH Full Featured RAT (Remote Access Trojan) payloads and associated CAgent11 implant builder/controller. This implant is used for standard system management, control and recon.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
option17: Create Persistence... 3 -> Create an hourly Scheduled Task called "System Backup"
"Create Persistence... 3 -> Create an hourly Scheduled Task called \"System Backup\""
These samples performs simple XOR network encoding and are capable of many features including conducting system surveys, file upload/download, process and command execution
Initial infection is carried out via a malicious executable. An embedded bitmap image (contained in the trojan) is decoded into shellcode upon execution, thus loading the implant.
option12/27/28: if True -> exploit dll hijack in cliconfg.exe (SQL Server Client Network Utility) dumps a number (option28) of bytes from an offset (option27) of this file into %temp%\ntwdblib.dll creates a Software\Claiomh registry key executes cliconfg.exe (which loads ntwdblib.dll)
option17: Create Persistence... 3 -> Create an hourly Scheduled Task called "System Backup"
"Create Persistence... 3 -> Create an hourly Scheduled Task called \"System Backup\""
option18/23: Process Hollowing vs Drop/Execute == 0 -> Do Process Hollowing
The implants are loaded with a trojanized executable containing a fake bitmap which decodes into shellcode which loads the embedded implant... Packets are encoded by performing an XOR on the data after the header with the XOR key 0x07.
option18/23: Process Hollowing vs Drop/Execute == 0 -> Do Process Hollowing
option19: Process to create/hollow/inject/execute 1 -> svchost.exe 2 -> conhost.exe 3 -> explorer.exe
option01: True -> check for vm artifacts... option02: True -> check for sandbox artifacts
option12/27/28: if True -> exploit dll hijack in cliconfg.exe (SQL Server Client Network Utility) dumps a number (option28) of bytes from an offset (option27) of this file into %temp%\ntwdblib.dll creates a Software\Claiomh registry key executes cliconfg.exe (which loads ntwdblib.dll)
Core functionality includes: ... Exfiltration of cached credentials
Core functionality includes: ... Keylogging ... Browser hijacking/form grabbing
The analyzed BISTROMATH samples ... attempt to evade analysis via common sandboxes ... via multiple artifact checks (presence of specific devices, registry entries, processes, files).
The implant initiates callback to C2, then immediately sends its victim_info... Language, Country, Victim_ID, Computer_Name, User_Name, Implant_Version, Victim_IP, System_Architecture, Drive_Letters, OS_Version
The controller can establish Remote Desktop viewer, drive enumeration, file upload/download
MITRE ATT&CK Lazarus Group – G0032 ... System Time Discovery – T1124
Core functionality includes: ... Keylogging ... Browser hijacking/form grabbing
The controller can establish... keylogger, browser activity, cached passwords
The controller can establish Remote Desktop viewer... and monitoring the microphone, clipboard, and the screen.
Description Hard-coded C2 address used by these RATs... a hardcoded C2 address of 159.100.250.231 on port 8080 is contained within the sample
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A full-featured remote access trojan attributed to Lazarus/Hidden Cobra that provides persistence, host control, reconnaissance, file and process manipulation, exfiltration, screenshot and microphone capture, webcam control, keylogging, browser hijacking/form grabbing, cached credential theft, and self-update/uninstall capabilities.
North Korean-associated full-featured remote access trojan/implant family with builder/controller components. It supports system surveys, file upload/download, process and command execution, microphone, clipboard, and screen monitoring, keylogging, browser activity and cached password collection, persistence, process hollowing, anti-VM/sandbox/debug checks, and dynamic implant building with configurable callback settings.
A full-featured RAT listed among Lazarus Group tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.