TYPEFRAME is a Windows malware family associated with North Korean state cyber activity tracked by the U.S. government as HIDDEN COBRA. It has been described as a tool set combining remote access trojan and proxy or tunneling functionality. Observed variants include 32-bit and 64-bit Windows executables, malicious DLL service modules, proxy components, and a malicious Microsoft Word document used to deliver a payload through VBA macros.
TYPEFRAME supports post-compromise remote control and staging of additional malicious capability. Reported functions include downloading and installing malware, deploying RAT and proxy modules, connecting to command-and-control infrastructure, executing shell commands, creating or terminating processes, searching for and transferring files, deleting files, and uninstalling itself. Some variants can execute processes with elevated privileges. Proxy-capable variants can turn a compromised host into a proxy server and modify local firewall settings to permit inbound access.
Persistence and concealment are achieved through Windows service installation and encrypted configuration storage in the Windows Registry. Variants have been observed installing malicious DLL modules as services and deleting services from victim systems. Configuration data has been stored in RC4-encrypted form in Registry locations associated with the malware’s RAT and proxy components. Additional unpacking and obfuscation behavior has been documented, including RC4 decryption and decompression of archived payloads as well as XOR decoding of embedded files before installation or execution.
A documented delivery mechanism for TYPEFRAME is a malicious Word document that prompts the user to enable macros, after which it decodes and executes an embedded PE payload. This places TYPEFRAME within the broader pattern of macro-enabled document delivery used in targeted intrusion activity. The malware is part of the Lazarus or HIDDEN COBRA ecosystem and has been linked to North Korean government operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware is designed to accept instructions from the remote server to perform the following functions: ... Execute command-using shell ...
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
attempted to lure victims into enabling malicious macros within email attachments... prompted victims to accept macros... Word documents containing malicious macros.
The RAT’s APIs and strings (registry key, file names, and service name) are RC4 encrypted... The malware decrypts the archive using the same RC4 key.
During analysis, the malware executed the file as C:\Windows\Temp\java.exe ... Company Name Microsoft Corporation ... Original Filename proquota.exe.mui
The malware is designed to accept instructions from the remote server to perform the following functions: ... Terminate processes ...
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
The malware attempts to connect to its C2 server 59.90.93.97 using port 443 and wait for further instructions.
This file is designed to open the Windows Firewall on the victim’s machine to allow incoming connections and force the compromised system to function as a proxy server.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
134 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Delivered via malicious Word documents with VBA macros for execution.
Malware with variants that decrypt archives using RC4 and decode embedded files using XOR.
Malware delivered via a Word document that prompts the user to enable macros.
Backdoor malware capable of deleting files from the system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.