Manuscrypt, also known as COPPERHEDGE in some reporting, is a Lazarus-associated remote access trojan used in long-running North Korean intrusion operations. It is a full-featured backdoor platform employed for espionage and financially motivated activity, including campaigns against defense organizations, cryptocurrency exchanges, decentralized-finance businesses, blockchain companies, and related entities. Public reporting places its use in Lazarus operations since at least 2013, with more than 50 campaigns documented across government, diplomatic, financial, military, telecommunications, gaming, media, academic, and security-research targets.
The malware is primarily associated with Windows, but Linux and Android variants have also been reported, indicating cross-platform development within the family. Windows variants support arbitrary command execution, host reconnaissance, process and file management, file transfer, configuration updates, timestomping, reflective loading, and data exfiltration. Reported Linux ELF variants share code and strings with Windows PE counterparts, while Android variants have been described as remote access trojans capable of surveillance and device control functions.
Manuscrypt is notable for its modularity and operational flexibility. Related Lazarus campaigns have used trojanized cryptocurrency applications and wallet software to deliver the malware, after which operators harvested system information and searched for cryptocurrency wallet keys or credentials to facilitate theft of funds. Other Lazarus operations linked to Manuscrypt used staged loaders, encrypted configuration data, multi-stage command-and-control relays, and code overlaps with Lazarus clusters such as ThreatNeedle and CookieTime. In defense-sector intrusions, loaders resembling Manuscrypt have been used to establish footholds and deploy later-stage implants.
The family has also been tied to watering-hole and software-lure operations, including campaigns abusing trusted websites or trojanized applications to infect victims. Across reporting, Manuscrypt and closely related COPPERHEDGE variants are characterized as persistent backdoors used to maintain access, conduct reconnaissance, execute operator commands, and exfiltrate victim data. In cryptocurrency-focused operations, the malware has been directly linked to theft enablement through credential and wallet-key collection. The family remains a significant component of the Lazarus toolset for both intelligence collection and revenue-generating cyber operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Google released an update and thanked us for discovering this attack... CVE-2024-4947... The exploit contains code for two vulnerabilities: the first is used to gain the ability to read and write Chrome process memory from the JavaScript... CVE-2024-4947 ... is the vulnerability in this new compiler. | We closely monitor their activities and quite often see them using their signature malware in their attacks — a full-feature backdoor called Manuscrypt.
"APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析" published by Qihoo360. | "APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析"
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware COPPERHEDGE RAT associated with Lazarus, observed in TraderTraitor activity. | In this way, TraderTraitor apps delivered malware such as MANUSCRYPT (a remote access trojan) onto victims’ systems. MANUSCRYPT would then harvest system info, execute arbitrary commands, and ultimately seek out cryptocurrency wallet keys or credentials to enable theft of funds.
Malware COPPERHEDGE RAT associated with Lazarus, observed in TraderTraitor activity. | In this way, TraderTraitor apps delivered malware such as MANUSCRYPT (a remote access trojan) onto victims’ systems. MANUSCRYPT would then harvest system info, execute arbitrary commands, and ultimately seek out cryptocurrency wallet keys or credentials to enable theft of funds.
We closely monitor their activities and quite often see them using their signature malware in their attacks — a full-feature backdoor called Manuscrypt.
Listed in the Wiz “TraderTraitor: Deep Dive” entry alongside GolangGhost and other tooling.
41 distinct techniques documented for this family, organized by ATT&CK tactic.
MANUSCRYPT would then harvest system info [T1082], execute arbitrary commands [T1059]
Shell commands use the shell path recorded in configuration and execute in the form /c "<command> > <temp file> 2>&1".
These malicious apps – built on JavaScript [T1059.007] and Node.js using the Electron framework
payloads delivered by the macros discussed in Operation Blockbuster Sequel ... malware used in the HiddenCobra threat group ... source code was reused between previously reported samples and the cluster of new samples
공격자는 워터링 홀 또는 스피어 피싱 등 다양한 방식으로 공격 대상의 악성 URL 접속을 유도한 후, 취약점을 익스플로잇하여 최종적으로 백도어 악성코드를 설치하였다.
the malware used in the attack loads its payload from the system registry and decrypts it. The payload’s location in the registry is unique for each infected system.
The ultimately executed malware communicates via HTTP/HTTPS... to perform remote command execution, file theft, shellcode execution, and process injection.
The C2 server could respond with an encrypted second stage payload (using AES-256 [T1027]) that the app would decrypt and execute
When the malware runs, it randomly generates dropped filenames and adds 60MiB ~ 80MiB of junk data.
Repeatedly reads hidden additional module data from two PNG file paths stored in configuration, decrypts it, and injects it into explorer.exe.
The identified malware commonly constructed a multi-stage loading chain that decrypts subsequent payloads using ChaCha20 or AES-128 algorithms...
It targets an empty slot whose name is already listed in netsvcs but has no actual service key... the service name is originally registered in Windows, making maliciousness hard to judge from the execution subject alone.
Dropped files are created in C:\Windows\System32 ... names such as edgsvc.dll, gsosvc.dat resemble normal system files... the dropper itself uses the normal system process name smss.exe.
PNG hiding uses normal image files with real PNG signatures... image viewers open them normally.
The ultimately executed malware communicates via HTTP/HTTPS... to perform remote command execution, file theft, shellcode execution, and process injection.
During initialization, it deletes the registry value containing configuration data, reads loader and backdoor data into memory, and then deletes the loader and backdoor files.
On shutdown, the loader, backdoor, configuration data, and Security Packages entry are restored...
If a 34-character argument is not passed, the malicious logic does not execute... Without the registry-stored configuration data, the loader cannot obtain the backdoor decryption key... TYPE 3 must read key and IV from its own :kgb ADS.
If the 34-character argument is absent, malicious logic does not execute... sandbox automatic analysis evasion... The backdoor waits until the configured activation time before beginning communications.
Collects ... IPv4 address of network adapters...
Command codes include file list query, directory statistics collection, and designated drive information query.
These domains and IPv4 addresses are used to generate crafted TLS sessions similarly to the 'fake TLS' communication mechanisms ... includes a legitimate domain name in its SNI field yet is sent to a command and control IPv4 address.
The configuration contains multiple C&C URLs... confirmed C&C server URLs are three, all domestic servers.
MITRE Tactic Technique & ID ... Command & Control Application Layer Protocol: Web Protocols (T1071.001) Malware uses HTTPS callbacks to C2 servers.
338 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage backdoor used in watering-hole attacks against South Korean targets. It is loaded reflectively in memory, stores encrypted configuration in the registry or NTFS ADS, communicates over HTTP/HTTPS with compromised South Korean web servers, and supports remote command execution, file theft, shellcode/PE execution, process injection, persistence via service hijacking and SSP registration, and self-protection by deleting/restoring artifacts.
Backdoor deployed in the campaign that supports remote command execution, file theft, internal reconnaissance, process injection, and delivery of additional payloads. One described infection chain decrypted later stages in memory, injected code into svchost.exe, and read command-and-control information from the Windows registry.
Named malware/tool referenced in the context of a watering hole attack technical analysis report.
A backdoor executed reflectively from memory by the loader. It stores encrypted configuration in the registry or NTFS ADS depending on mode, establishes persistence via service hijacking and SSP registration, collects host information, communicates with multiple C2 URLs using ChaCha20/XOR/Base64-protected POST traffic, supports command execution, and can decrypt and inject additional modules into explorer.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.