Skip to content

Malware

TYPEFRAME

TYPEFRAME is a RAT. It supports ~25 commands that include operations on the victim’s filesystem, manipulation with its configuration, modification of the system's firewall, the download and execution

TYPEFRAME is a Windows malware family operated by Lazarus Group.

Background

TYPEFRAME is a remote access trojan.

It offers roughly 25 commands covering actions on the victim's filesystem, changes to its own configuration, alteration of the host's firewall, retrieval and execution of further tools from the attacker's C&C, and removal of itself through a self-delete batch file. Each command is referenced by a 16-bit integer index beginning at 0x8000.

The RAT decrypts its binary configuration with RC4 and includes a statically linked OpenSSL 0.9.8k library to handle SSL communication.


Source: Malpedia (Fraunhofer FKIE).