Researchers and incident responders documented a targeted intrusion campaign by CryptoMimic—also tracked as Dangerous Password, CageyChameleon, and Leery Turtle—that focused on banks, financial organizations, and especially cryptocurrency businesses. The attacks used spear-phishing lures that delivered ZIP or RAR archives containing malicious .lnk shortcut files and decoy documents; when opened, the shortcuts launched mshta.exe to fetch remote HTML or VBScript payloads. JPCERT/CC said the activity hit Japanese organizations tied to cryptocurrency operations, while later analysis captured a full intrusion chain in which the initial script deployed staged implants including Cabbage RAT variants, a browser information stealer, msoRAT, and a credential theft component that abused Windows Security Packages.
Across the reports, the malware showed consistent tradecraft: persistence through Startup-folder shortcuts and registry changes, victim filtering and antivirus checks, host reconnaissance via WMI, and command-and-control through Bitly links and spoofed cloud-themed domains such as cloudfiles.club and msupdatepms.xyz. The operators collected browser cookies, saved passwords, OS and hardware details, process lists, and likely system credentials, then used interactive follow-on access, including legitimate VNC tools, for manual post-compromise activity and possible cryptocurrency theft. Investigators also observed cleanup actions such as event log deletion and destructive behavior, and noted that the tooling and operational patterns shared multiple similarities with activity previously linked to Lazarus, though attribution remained unconfirmed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
An April 2020 analysis reported that the malware's reconnaissance format and tradecraft were consistent with activity observed since mid-2019. It also assessed the campaign as focused on cryptocurrency theft and likely involving manual post-compromise actions.
The researchers monitored 15 CryptoMimic attacks during March 2020 and noted no attacks on Sundays. The observations reinforced that the actor's tactics had remained stable while targeting finance and cryptocurrency victims.
Researchers observed a complete CryptoMimic intrusion in February 2020 that unfolded in about three hours. The chain progressed from a phishing-delivered LNK file through multiple Cabbage RAT stages, a browser information stealer, msoRAT, and a credential stealer.
As of 26 June 2019, JPCERT/CC reported that it could not confirm details of update.gdrives.top because the hostname no longer resolved. This showed the attackers had already made parts of the infrastructure unavailable to analysis.
A later analysis cited a June 2019 Japanese CERT report as documenting the same categories of host data collection, including VBS execution path, network adapter information, and running processes. This tied the observed intrusion chain to activity seen since mid-2019.
JPCERT/CC observed targeted emails sent to some Japanese organizations beginning in June 2019. The campaign used cloud-hosted ZIP downloads containing a password-protected decoy document and a malicious Password.txt.lnk shortcut that launched mshta.exe to fetch VBScript.
Researchers assessed that the CryptoMimic threat actor had been active since around March or April 2018, using largely consistent tradecraft. The group targeted banks, finance organizations, and especially cryptocurrency-related companies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceblogs.jpcert.or.jp
Open sourcevb2020.vblocalhost.com
Open sourcevb2020.vblocalhost.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.