Manuscrypt

First seen
2009-12-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 14:22:17

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Targeted regions: country_code:kr country_code:us country_code:jp

Context

Manuscrypt is a backdoor typically associated with advanced persistent threat (APT) groups, specifically believed to be linked to North Korean operators. It has been deployed in various cyber-espionage campaigns targeting government, defense, and technology sectors.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Dropper_Mac_Lazarus_Manuscrypt (yara-rule)
  • MALPEDIA_Win_Pseudo_Manuscrypt_Auto (yara-rule)

Reports & references

  • blackberry.com — Report Bb 2021 Threat Report (report)
  • wiz.io — North Korean Tradertraitor Crypto Heist (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Manuscrypt (report)
  • twitter.com — 1337330286787518464 (report)
  • anquanke.com — 223817 (report)
  • twitter.com — 1321488299932983296 (report)

External references