PondRAT is a cross-platform remote access trojan associated with North Korean Lazarus Group activity, with variants for Windows, Linux, and macOS. It provides remote file upload and download, file reading and writing, process execution, arbitrary shell-command execution, and configurable pauses in operation. Analyzed Windows variants also support loading portable executable payloads into memory and executing shellcode. PondRAT communicates with hardcoded command-and-control servers over HTTP or HTTPS, using XOR encryption and Base64 encoding for its messages. Windows variants securely erase temporary command-output files through overwriting and repeated renaming before deletion.
PondRAT has been distributed through malicious Python packages uploaded to PyPI. Installing these packages triggers an encoded intermediate stage that retrieves and executes Linux or macOS payloads. Its distribution has been associated with job-offer lures targeting developers. PondRAT has also been deployed alongside ThemeForestRAT in intrusions against financial and cryptocurrency organizations, serving as an initial-access implant for deploying additional malware. It shares substantial code and behavioral similarities with POOLRAT. In an observed intrusion, operators used PondRAT and ThemeForestRAT for approximately three months before replacing them with the more advanced RemotePE toolset.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“PondRAT was the initial access payload used to deploy other types of malware, including ThemeForestRAT.”
In one investigation, we observed that the actor had replaced ThemeForestRAT and PondRAT with a more sophisticated memory-only toolset.
Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE
5 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An older implant previously used by the threat actors before transitioning to the newer memory-only Lazarus toolset.
An older Lazarus-linked RAT referenced for overlap in secure deletion behavior and as prior tooling replaced by the newer framework.
A Lazarus RAT referenced as an older tool replaced by RemotePE; the article also notes a seven-pass overwrite pattern in RemotePE consistent with PondRAT.
A RAT previously associated with this Lazarus subgroup; the article notes RemotePE shares a secure deletion pattern consistent with PondRAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.