Skip to content

Malware

miniBlindingCan

aka AIRDRY.V2 · EventHorizon

miniBlindingCan is an HTTP(S) orchestrator.

miniBlindingCan, also known as AIRDRY.V2, EventHorizon, is a Windows malware family operated by Lazarus Group.

Background

miniBlindingCan is an orchestrator that communicates over HTTP(S).

It descends from the BlindingCan RAT, reusing the same command-parsing logic while implementing only a limited subset of the commands found in the original. Its principal tasks are updating the malware's configuration and pulling down and running further payloads from the operators' C&C.

This malware featured in Operation DreamJob campaigns aimed at aerospace and media organizations during Q2-Q3 2022.


Source: Malpedia (Fraunhofer FKIE).