Malware
wAgentTea
aka wAgent
wAgentTea is an HTTP(S) downloader. It was deployed mostly against South Korean targets like a pharmaceutical company (Q4 2020) or semiconductor industry (Q2 2023).
wAgentTea, also known as wAgent, is a Windows malware family operated by Lazarus Group.
Background
wAgentTea is a downloader that communicates over HTTP(S).
It has mainly been used against South Korean victims, such as a pharmaceutical company in Q4 2020 and the semiconductor sector in Q2 2023. In a number of incidents, initial access came from exploiting South Korean software like Initech's INISAFE CrossWeb EX or Dream Security's MagicLine4NX.
It applies AES-128 to encrypt and decrypt its network traffic as well as to decrypt its binary configuration.
Its HTTP POST requests draw on a fixed, hard-coded set of parameter names: identy;tname;blogdata;content;thesis;method;bbs;level;maincode;tab;idx;tb;isbn;entry;doc; category;articles;portal
The binary also includes a distinctive RTTI symbol, ".?AVCHttp_socket@@".
Source: Malpedia (Fraunhofer FKIE).