miniBlindingCan
Aliases: AIRDRY.V2, EventHorizon
- First seen
- 2022-04-01 00:00:00
- Malware type
- rat, downloader
- Profile updated
- 2026-07-07 14:29:48
Targeted industries: defense-and-aerospace media-and-entertainment
Context
miniBlindingCan is an HTTP(S) orchestrator. It is a variant of the BlindingCan RAT, having the same command parsing logic, but supporting only a small subset of commands available previously. The main operations are the update of the malware configuration, and the download and execution of additional payloads from the attackers' C&C. The miniBlindingCan malware was used in Operation DreamJob attacks against aerospace and media companies in Q2-Q3 2022.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Miniblindingcan_Auto (yara-rule)
Reports & references
- virusbulletin.com — Lazarus Campaigns And Backdoors In 2022 2023 (report)
- Mandiant — Dprk Whatsapp Phishing (report)
- Microsoft — Zinc Weaponizing Open Source Software (report)
- ESET — Lazarus Luring Employees Trojanized Coding Challenges Case Spanish Aerospace Company (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Miniblindingcan (report)