Racket Downloader

First seen
2021-04-01 00:00:00
Malware type
downloader
Family
Malware family
Profile updated
2026-07-07 14:48:16

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr

Context

Racket Downloader is an HTTP(S) downloader. It uses a custom substitution cipher for decryption of its character strings, and RC5 with a 256-bit key for encryption and decryption of network traffic. It sends an HTTP POST request containing a particular value that inspired its name, like "?product_field=racket" or "prd_fld=racket". Racket Downloader was deployed against South Korean targets running the Initech INISAFE CrossWeb EX software in Q2 2021 and Q1 2022.

Reports & references

  • Kaspersky — 109490 (report)
  • asec.ahnlab.com — 40495 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Racket (report)
  • asec.ahnlab.com — 33801 (report)
  • medium.com — Analysis Of Lazarus Malware Abusing Non Activex Module In South Korea 7D52B9539C12 (report)
  • Broadcom/Symantec — Lazarus Dream Job Chemical (report)

External references