Malware
miniBlindingCan
aka AIRDRY.V2 · EventHorizon
miniBlindingCan is an HTTP(S) orchestrator.
miniBlindingCan, also known as AIRDRY.V2, EventHorizon, is a Windows malware family operated by Lazarus Group.
Background
miniBlindingCan is an orchestrator that communicates over HTTP(S).
It descends from the BlindingCan RAT, reusing the same command-parsing logic while implementing only a limited subset of the commands found in the original. Its principal tasks are updating the malware's configuration and pulling down and running further payloads from the operators' C&C.
This malware featured in Operation DreamJob campaigns aimed at aerospace and media organizations during Q2-Q3 2022.
Source: Malpedia (Fraunhofer FKIE).