Kaspersky ICS CERT reported that the PseudoManuscrypt spyware campaign infected more than 35,000 computers in 195 countries, including government, industrial, engineering, and military-industrial organizations, with at least 7.2% of affected systems identified as ICS computers. The malware was distributed at scale through a malware-as-a-service ecosystem using fake pirated software installers, including installers for some ICS-related software, and in some cases through Glupteba infrastructure. Once installed, PseudoManuscrypt gave attackers broad espionage and control capabilities, including keylogging, clipboard theft, VPN credential theft, screen capture, microphone recording, event log access, hosts-file manipulation, and the ability to disable security tools.
Researchers said the malware stored an encrypted payload in the Windows registry, persisted as a service, and used a KCP-based command-and-control mechanism previously seen in tooling linked by FireEye to APT41. Kaspersky found technical overlaps with both Lazarus Manuscrypt and infrastructure tied to Glupteba, but said the campaign’s opportunistic distribution model and global scale did not support firm attribution. Separate reporting on Glupteba showed it spreading inside enterprise networks through MS17-010/EternalBlue-related activity, underscoring the risk that commodity malware infrastructure can deliver high-end spyware into enterprise and operational technology environments.

Pull IOCs and campaign context straight into your stack.
22 events from the most recent confirmed update back to the earliest known activity.
Researchers developed a custom sinkhole for PseudoManuscrypt and monitored the botnet for more than eight months. Their tracking observed roughly 16,000 daily infected machines before a newer version and C2 change reduced daily counts to about 7,000, with a brief spike to around 51,500 unique client IDs.
Kaspersky ICS CERT published its analysis of the mass-scale PseudoManuscrypt spyware campaign, detailing distribution through fake pirated installers and occasional Glupteba-linked delivery.
Between January 20 and November 10, 2021, Kaspersky blocked PseudoManuscrypt on more than 35,000 computers in 195 countries, including a notable share of ICS systems.
A second PseudoManuscrypt variant discovered in July 2021 added screen video capture, QQ and WeChat credential theft, expanded host and network reconnaissance, and attempts to disable security products.
Kaspersky ICS CERT identified the malware family in June 2021 and named it PseudoManuscrypt because its loader resembled Lazarus-associated Manuscrypt without sufficient evidence for attribution.
Kaspersky reported that mass distribution of the PseudoManuscrypt loader variant analyzed in its report began on May 10, 2021.
AhnLab ASEC reported that PseudoManuscrypt had been distributed in South Korea since May 2021, mainly disguised as illegal software installers such as cracks, keygens, and Windows activators delivered through malicious search-result websites. ASEC said numerous PCs in Korea were infected and observed about 30 infected systems per day on average.
Kaspersky telemetry indicated that early PseudoManuscrypt variants were first identified on March 27, 2021.
FireEye said it observed APT41's broad exploitation campaign from January 20 through March 11, 2020, marking the end of the activity window described in the report.
Beginning March 8, 2020, FireEye observed APT41 attempt exploitation of CVE-2020-10189 at more than a dozen customers and compromise at least five of them.
ManageEngine released an update containing a long-term fix for CVE-2020-10189 one day before FireEye observed APT41 exploitation attempts.
Researcher Steven Seeley published an advisory and proof-of-concept code for the Zoho ManageEngine Desktop Central zero-day RCE CVE-2020-10189.
FireEye observed a significant uptick in APT41's Citrix exploitation activity on February 24–25, 2020, with payload delivery behavior similar to earlier February activity.
On February 21, 2020, APT41 successfully exploited a Cisco RV320 router at a telecommunications organization and downloaded an ELF payload from attacker infrastructure.
Beginning February 1, 2020, FireEye observed APT41 move from simple validation commands to payload retrieval via FTP in its Citrix exploitation activity.
Citrix released permanent fixes for supported versions affected by CVE-2019-19781. FireEye referenced these fixes in the context of APT41 exploitation.
ManageEngine released a short-term mitigation for the Desktop Central zero-day CVE-2020-10189 ahead of observed APT41 exploitation.
FireEye observed APT41 begin a large-scale intrusion campaign targeting internet-facing systems at more than 75 customers. Initial activity started with exploitation attempts against Citrix ADC and Gateway devices.
Citrix published a mitigation for CVE-2019-19781 before APT41's later exploitation activity. FireEye cited this as the vendor response preceding the campaign.
K7 Labs stated that Glupteba was first seen in 2014, providing the earliest anchored date for the malware family referenced in the story.
An ESET WeLiveSecurity post documented Glupteba alongside TDL4, establishing Glupteba's presence in the threat landscape by 2011.
K7 Labs reported a recent spike in Glupteba detections, indicating the malware had become active again after fading around 2020. The observed activity included lateral movement attempts using SMB exploitation associated with MS17-010.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 53 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
bitsight.com
Open sourceasec.ahnlab.com
Open sourceics-cert.kaspersky.com
Open sourceics-cert.kaspersky.com
Open sourcelabs.k7computing.com
Open sourcesecurelist.com
Open sourcefireeye.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.