CROWDEDFLOUNDER is a North Korea-linked Windows remote access trojan associated with HIDDEN COBRA, also known as Lazarus Group activity. It is a 32-bit, Themida-packed, memory-resident implant that unpacks and executes in memory, accepts runtime arguments, and can be installed as a Windows service for persistence. The malware has been characterized as a full-function RAT, but it is notably used to proxy communications by either listening for inbound connections on a specified port or connecting outbound to a remote command-and-control server.
CROWDEDFLOUNDER modifies local firewall settings to permit its network traffic and protects command-and-control sessions and data transfers with a rotating XOR scheme. In outbound mode it has been observed using cURL for data transfer operations. The malware supports file upload and download, execution of secondary payloads and shell commands, process termination, file deletion and search, file attribute changes, and collection of host and storage information. It also supports securely retrieving malicious DLL payloads for injection into remote processes, extending its post-compromise utility.
The malware has been publicly attributed by U.S. government reporting to North Korean government cyber operations and is part of a broader Lazarus tooling ecosystem that includes other remote access, proxying, and tunneling implants. Its design emphasizes covert in-memory execution, flexible command-and-control, host manipulation, and proxy functionality on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CROWDEDFLOUNDER functions as a memory-resident RAT (32-bit and Themida packed). The malware accepts arguments at runtime, and can be installed as a service.
Some of the malware variants in this report, such as CROWDEDFLOUNDER, HOPLIGHT, and ELECTRICFISH were previously reported...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The RAT uses a rotating exclusive or (XOR) cryptographic algorithm to secure its data transfers and command-and-control (C2) sessions
It is designed to listen as a proxy for incoming connections containing commands or can connect to a remote server to receive commands.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A memory-resident Lazarus/Hidden Cobra RAT that supports two-way C2 communications and appears primarily used as a proxy for inbound C2 connections, while also enabling firewall manipulation, reconnaissance, exfiltration, input capture, and command/process execution.
Full-function RAT.
A Themida-packed 32-bit Windows remote access trojan that unpacks and executes a RAT in memory, can run as a service or via command-line arguments, opens Windows Firewall ports, acts as a proxy listener or connects outbound to a remote C2 server, uses rotating XOR to protect C2 traffic, and supports file transfer, command execution, process termination, file deletion/search, system and storage enumeration, and malicious DLL download/injection into remote processes.
Some of the malware variants in this report, such as CROWDEDFLOUNDER, HOPLIGHT, and ELECTRICFISH were previously reported...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.