BUFFETLINE is a Windows beaconing implant attributed to the North Korean Lazarus Group, also tracked as Hidden Cobra. It is a full-featured remote access implant designed for post-compromise host control and operator tasking. Reported capabilities include system enumeration, upload, download, deletion, and execution of files, creation and termination of processes, and enabling command-line access on infected hosts. After establishing contact, the implant transmits victim system information and then waits for commands from its controller.
The malware uses obfuscated API resolution and protects portions of its strings and protocol elements with a modified RC4-based routine. For command-and-control communications, it performs session authentication using PolarSSL and then switches to a custom FakeTLS-style encoding scheme rather than relying on the negotiated TLS session key. This approach is intended to make traffic resemble legitimate encrypted sessions while retaining attacker-controlled packet formatting and payload encryption.
BUFFETLINE has been described as a RAT-like beacon implant used in North Korean government cyber operations. Its role is consistent with persistence and interactive post-exploitation on compromised Windows systems, supporting remote execution and file operations needed for follow-on intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BUFFETLINE is a full, beacon-style, implant with RAT-like functionality.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The sample performs dynamic DLL importing and API lookups using LoadLibrary and GetProcAddress on obfuscated strings in an attempt to hide it’s usage of network functions. The sample obfuscates strings used for API lookups as well as the strings used during the network handshake using a modified RC4 algorithm.
Data transferred includes: · Hardware details (network adapters, CPU revision) ... · Victim IP Address
This report looks at a full-featured beaconing implant. This sample uses PolarSSL for session authentication, but then utilizes a FakeTLS scheme for network encoding using a modified RC4 algorithm. | The sample attempts to perform a PolarSSL handshake to initiate a connection to each of these hardcoded C2 IPs using TLS version 1.1.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus/Hidden Cobra beacon-style implant with RAT-like functionality that performs file and process manipulation, reconnaissance, exfiltration, lateral targeting and enumeration, command execution, and transmits detailed victim host information after authenticating to C2.
A North Korean-linked full-featured beaconing implant/backdoor that performs dynamic DLL importing and obfuscated API lookups, connects to hardcoded C2 servers over TLS 1.1 using PolarSSL for authentication, then switches to a custom 'FakeTLS' protocol with XOR/modified RC4-style encryption. It can download, upload, delete, and execute files, enable Windows CLI access, create and terminate processes, and enumerate the victim system.
A Lazarus implant using RC4 encoding and PolarSSL to obfuscate network communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.