HOTWAX

Malware type
trojan, loader
Profile updated
2026-07-07 12:46:06

Context

HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file. HOTWAX decrypts a payload using the Spritz algorithm with a hard-coded key and then searches the target process and attempts to inject the decrypted payload module from the CHM file into the address space of the target process.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Hotwax_Auto (yara-rule)

Reports & references

  • Kaspersky — 77908 (report)
  • Mandiant — Rpt Apt38 (report)
  • virusbulletin.com — Vb2018 Kalnai Poslusny (report)
  • ESET — Demystifying Targeted Malware Used Polish Banks (report)
  • media.kasperskycontenthub.com — Lazarus Under The Hood Pdf Final (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Hotwax (report)
  • raw.githubusercontent.com — Group Ib Lazarus (report)
  • baesystemsai.blogspot.com — Lazarus False Flag Malware (report)

External references