Manuscrypt
- First seen
- 2009-12-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 14:22:17
Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications
Targeted regions: country_code:kr country_code:us country_code:jp
Context
Manuscrypt is a backdoor typically associated with advanced persistent threat (APT) groups, specifically believed to be linked to North Korean operators. It has been deployed in various cyber-espionage campaigns targeting government, defense, and technology sectors.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Dropper_Mac_Lazarus_Manuscrypt (yara-rule)
- MALPEDIA_Win_Pseudo_Manuscrypt_Auto (yara-rule)
Reports & references
- blackberry.com — Report Bb 2021 Threat Report (report)
- wiz.io — North Korean Tradertraitor Crypto Heist (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Manuscrypt (report)
- twitter.com — 1337330286787518464 (report)
- anquanke.com — 223817 (report)
- twitter.com — 1321488299932983296 (report)