Skip to content

Malware

wAgentTea

aka wAgent

wAgentTea is an HTTP(S) downloader. It was deployed mostly against South Korean targets like a pharmaceutical company (Q4 2020) or semiconductor industry (Q2 2023).

wAgentTea, also known as wAgent, is a Windows malware family operated by Lazarus Group.

Background

wAgentTea is a downloader that communicates over HTTP(S).

It has mainly been used against South Korean victims, such as a pharmaceutical company in Q4 2020 and the semiconductor sector in Q2 2023. In a number of incidents, initial access came from exploiting South Korean software like Initech's INISAFE CrossWeb EX or Dream Security's MagicLine4NX.

It applies AES-128 to encrypt and decrypt its network traffic as well as to decrypt its binary configuration.

Its HTTP POST requests draw on a fixed, hard-coded set of parameter names: identy;tname;blogdata;content;thesis;method;bbs;level;maincode;tab;idx;tb;isbn;entry;doc; category;articles;portal

The binary also includes a distinctive RTTI symbol, ".?AVCHttp_socket@@".


Source: Malpedia (Fraunhofer FKIE).