Fortinet researchers analyzed samples of the NukeSped malware and found that it bears many similarities to malware used by the North Korea -linked hacking Lazarus group . The researchers believe it is a new weapon from this APT group.
Two months ago, Intezer and McAfee collaborated to conduct a study on code in malware. The researchers found that some APT groups share parts of the same code to create their malware.
After analyzing thousands of malware samples, researchers found many similarities in the source code used in attacks related to North Korea.
For example, the “Common SMB module” was part of the WannaCry Ransomware (2017). Researchers noticed that it closely resembled the code of the Mydoom (2009), Joanap, and DeltaAlfa malware.
In the current study, Fortinet researchers analyzed new samples, which they associated with the Lazarus hacking group, as they observed similarities to the malware it used in previous attacks.
According to the analysis, all samples were related to the Korean language, were compiled for 32-bit systems, and used encrypted strings.
NukeSped essentially functions as a RAT, giving attackers the ability to remotely manage the infected computer.

What are the features of NukeSped RAT?
- Repeating files in a folder
- Creating processes
- Process editing
- Ending processes
- File writing
- Reading a file
- Move file
- Remote computer connection
- Retrieving and launching payload from the internet
- Get information about installed disks (disk type, free space, etc.)
- Get the current directory
- Change directory
- Removing oneself and one's activities from the infected system
Linking malware to a specific hacking group is not an easy task.
Fortinet researchers had to do a lot of analysis and examine specific characteristics to conclude that the NukeSped RAT is linked to North Korean , specifically the Lazarus Group.
