The Lazarus APT Group has unveiled a new Remote Access Trojan called ScoringMathTea, which represents a significant advancement in cyberattack capabilities.
See also: Kimsuky and Lazarus teams use new tools

This C++-based malware was identified as part of Operation DreamJob, a campaign linked to the North Korean government.
Threat actors are targeting companies that provide drone technology to Ukraine, aiming to steal critical production knowledge and intellectual property.
ScoringMathTea is distributed via two distinct extermination chains and provides operators with complete control over compromised systems.
The malware allows remote command execution, plugin loading into memory, and various persistence mechanisms that allow attackers to maintain long-term access to infected networks.
What makes this threat particularly dangerous is its sophisticated architecture that is specifically designed to evade detection in both network and endpoint security systems.
See also: 2025: North Korean hackers have stolen $2 billion in crypto

A security analyst and researcher, 0x0d4y, noted that ScoringMathTea implements multiple layers of obfuscation and evasion techniques.
The malware uses a custom polyalphabetic chained substitution cipher to unscramble strings at runtime, making static analysis significantly more difficult for security teams.
The decryption mechanism uses a 64-character lookup table and maintains a dynamic key state that changes with each character, effectively preventing simple string extraction tools from revealing its configuration details.
The malware's most notable defensive feature is its implementation of the hashing API for dynamic analysis. Instead of calling Windows APIs directly, ScoringMathTea resolves the APIs at runtime using a custom hashing algorithm.
See also: Lazarus team exploits Git symlink vulnerability

The algorithm operates with a fixed seed value of 0x2DBB955 and combines ASCII character values with bit-shifted hash functions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
