A malware campaign targeting Korean users distributed Orcus RAT and XMRig by disguising the payload as a cracked installer for Hangul Word Processor 2022 on file-sharing sites. AhnLab said the installer used 7z SFX archives, obfuscated PowerShell, Windows Defender exclusion changes, Google Docs-hosted payload retrieval, NirCmd, and scheduled tasks to evade detection and maintain persistence. The downloader checked for analysis environments and installed security tools, exfiltrated host details through the Telegram API, and then selectively deployed a coin miner or additional malware components. On some systems, particularly those with Telegram or Visual Studio installed, the actor installed Orcus RAT and enabled broad remote access, including keylogging, webcam access, remote desktop control, and RDP activation through an OrcusRDP account.
The activity reflects the continued criminal use of Orcus, a commercially sold modular RAT previously documented by Palo Alto Networks Unit 42 as a low-cost malware platform with plugin support and live scripting capabilities. Unit 42 reported that Orcus was built around separate controller, server, and victim components and supported functions such as password theft, remote code execution, webcam and microphone monitoring, reverse proxying, and hidden virtual network computing. The Korean campaign also showed anti-analysis behavior consistent with Orcus tradecraft, including checks for virtualized environments and monitoring tools, while the bundled XMRig miner was injected into explorer.exe, paused during games or monitoring activity, and attempted to kill security-related processes to hinder remediation.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Orcus started being sold for about $40, with Unit 42 identifying "Sorzus" and partner "Armada" as the main people behind its development, sales, and support. The malware was marketed as a remote administration tool despite its malicious capabilities.
Around October 2015, the developer using the alias "Sorzus" posted about the malware, then called "Schnorchel," on a hacker forum and asked for feedback on publishing it. Forum users encouraged commercialization instead of releasing it for free or open source.
ASEC identified a campaign distributing malware through file-sharing sites as a cracked Hangul Word Processor 2022 installer. The installer deployed XMRig CoinMiner broadly and installed Orcus RAT instead of the actor's previously used BitRAT on some systems, especially when Telegram or Visual Studio was present.
ASEC said the same threat actor had earlier distributed BitRAT and XMRig CoinMiner on file-sharing sites while disguising them as a Windows license verification tool. This earlier campaign primarily targeted Korean users through file-sharing sites and torrents.
Palo Alto Networks Unit 42 reported on Orcus, describing its modular controller-server-trojan architecture, plugin ecosystem, real-time scripting, delivery vectors, and anti-analysis checks. The report assessed Orcus as a malicious RAT and documented its growing criminal utility.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.