miniBlindingCan

Aliases: AIRDRY.V2, EventHorizon

First seen
2022-04-01 00:00:00
Malware type
rat, downloader
Profile updated
2026-07-07 14:29:48

Targeted industries: defense-and-aerospace media-and-entertainment

Context

miniBlindingCan is an HTTP(S) orchestrator. It is a variant of the BlindingCan RAT, having the same command parsing logic, but supporting only a small subset of commands available previously. The main operations are the update of the malware configuration, and the download and execution of additional payloads from the attackers' C&C. The miniBlindingCan malware was used in Operation DreamJob attacks against aerospace and media companies in Q2-Q3 2022.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Miniblindingcan_Auto (yara-rule)

Reports & references

  • virusbulletin.com — Lazarus Campaigns And Backdoors In 2022 2023 (report)
  • Mandiant — Dprk Whatsapp Phishing (report)
  • Microsoft — Zinc Weaponizing Open Source Software (report)
  • ESET — Lazarus Luring Employees Trojanized Coding Challenges Case Spanish Aerospace Company (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Miniblindingcan (report)

External references