Skip to content

Malware

BabyShark

aka LATEOP

BabyShark is Microsoft Visual Basic (VB) script-based malware family first seen in November 2018.

BabyShark, also known as LATEOP, is a Windows malware family operated by Kimsuky.

Background

BabyShark is a malware family built on Microsoft Visual Basic (VB) script that was first observed in November 2018. Infection begins by running a first-stage HTA pulled from a remote host, which allows delivery through a variety of file types, including PE files and weaponized documents. Once active, it sends system information back to a C2 server, establishes persistence on the host, and awaits further commands from its operator.


Source: Malpedia (Fraunhofer FKIE).