OAK — OnChain Attack Knowledge

Software · OAK-S10 · malware

OAK-S10 — Manuscrypt

Type
malware
Aliases
Manuscrypt (Kaspersky-original naming, retained as the most-used industry label); KEYMARBLE (NCCIC / US-CERT 2018 catalogue naming for an overlapping component / variant); FALLCHILL (CISA / FBI naming for an earlier Lazarus Windows backdoor with documented code overlap with later Manuscrypt builds); NukeSped (alternate naming used by some CTI vendors for related Lazarus Windows tooling); Volgmer is a related-but-distinct Lazarus Windows backdoor sometimes confused with Manuscrypt in older catalogues; the Manuscrypt name is canonical for the multi-stage Windows backdoor family used by Lazarus through 2017–2024 and is anchored in external cyber-threat-intel taxonomy Software entry S0259.
Active
yes (continued evolution; updated builds observed in incidents through 2024 per Kaspersky, ESET, and AhnLab reporting).
First observed
~2014–2015 (early variants under FALLCHILL naming); Manuscrypt naming consolidated approximately 2017 alongside the Lazarus crypto-pivot; long-running family that pre-dates the modern crypto-theft cluster but has been adapted continuously into it.
Used by Groups
OAK-G01 (Lazarus / DPRK-attributed cluster — confirmed via U.S. CERT advisories, FBI public statements, and multi-vendor industry-forensic corroboration).
Host platforms
Windows (long-running Windows-only family; macOS and Linux-side DPRK tooling sits in the AppleJeus / RustBucket / KandyKorn lineage rather than the Manuscrypt lineage).
Observed Techniques
OAK-T11.001 (third-party signing/custody-vendor compromise — Manuscrypt is a canonical second-stage backdoor staged after AppleJeus / TraderTraitor initial-access payloads land on Windows victim workstations within the vendor / exchange / custody perimeter), OAK-T10.001 (validator / signer key compromise — Manuscrypt has been observed in incidents leading to validator-key extraction in the 2017–2019 pre-DeFi crypto-exchange compromise wave). Pre-incident initial-access vectors are out of OAK v0.1 on-chain Tactic scope.

Description

Manuscrypt is a long-running multi-stage Windows backdoor family attributed to the OAK-G01 Lazarus cluster, with deployment history spanning approximately 2014–2015 (under earlier FALLCHILL / Volgmer naming for related families) through continuous updates into 2024–2025 builds. The family is Lazarus's workhorse Windows backdoor — the persistent-access tooling that operates downstream of the AppleJeus / TraderTraitor initial-access vectors (or in parallel via direct spear-phishing) and provides the hands-on-keyboard intrusion capability that runs the post-access portion of the kill chain. The external cyber-threat-intel taxonomy Software entry S0259 anchors the canonical industry-tracked family profile.

Infection vector for Manuscrypt is overwhelmingly post-initial-access staging: Manuscrypt is rarely the first-stage payload (that role is played by AppleJeus / TraderTraitor lineage on macOS and by FALLCHILL / NukeSped / direct-phish payloads on Windows). Once deployed, Manuscrypt provides multi-stage modular capability — file exfiltration, command execution, lateral movement support, credential harvesting, and second-stage payload delivery — with extensive evasion engineering (anti-VM checks, anti-debugging routines, control-flow obfuscation, encrypted-string handling, sandbox-detection logic, and per-victim build customisation that defeats hash-only detection). Persistence is established via combinations of registry Run keys, scheduled tasks, service installation, DLL search-order hijacking, and (in later builds) WMI event subscription. C2 communication uses HTTPS-over-port-443 with custom protocol obfuscation, frequent rotation of operator infrastructure, and (in some variants) blockchain-based or steganography-based command-channel patterns documented by Kaspersky and ESET.

The family's role in the DPRK financial-funding chain is post-access persistence and lateral movement — the bridge between initial-access compromise and the on-chain extraction Tactics that produce the final theft. In the 2017–2019 pre-DeFi era, Manuscrypt was the dominant tool for centralised-exchange compromises that ended in hot-wallet drains (Coincheck January 2018, KuCoin September 2020, multiple smaller exchange incidents). In the 2020-onwards era, Manuscrypt has continued in service alongside the macOS-side lineage and is staged on Windows victim workstations within mixed Windows / macOS crypto-firm environments. Defenders should treat Manuscrypt as the Windows persistence layer of the DPRK-against-crypto-industry intrusion tradecraft, complementing the AppleJeus / TraderTraitor entry-vector layer.

Observed examples

  • Coincheck (January 2018, ~$534M). Lazarus-attributed exchange hack with Manuscrypt-family Windows tooling reported in the post-mortem chain ([mandiantcoincheck2018] and related industry coverage). Inferred-strong attribution at incident time; subsequently corroborated by FBI and Japan NPA. Pre-DeFi era canonical case.
  • KuCoin (September 2020, ~$281M). Wallet-cluster attribution to Lazarus per Chainalysis ([chainalysiskucoinlazarus]) with Manuscrypt-family Windows backdoor tooling inferred from the cluster's broader 2020-era toolkit. Confirmed-grade Lazarus attribution; family-level naming is inferred-strong.
  • Multiple 2017–2019 exchange compromises. Manuscrypt has been documented in industry post-mortems for incidents at Bithumb, Yapizon / Youbit, and other Korean and Asian exchanges in the 2017–2019 cohort; per-incident attribution strength varies but cluster-level OAK-G01 attribution is confirmed via FBI / DOJ public statements.
  • Continuing 2020–2025 service alongside macOS-side lineage. Updated Manuscrypt builds observed in incidents through 2024 per Kaspersky, ESET, and AhnLab Security Emergency Response Center (ASEC) reporting; the family persists as the Windows persistence layer in mixed-environment crypto-firm intrusions.

Detection / attribution signals

  • Process-tree fingerprints — multi-stage execution patterns where an initial loader (frequently delivered as a self-extracting executable, ISO, or LNK-shortcut payload) drops and executes a stager that in turn drops Manuscrypt; the stager-and-final-payload pattern is itself a behavioral fingerprint distinct from single-stage commodity malware.
  • Persistence-mechanism fingerprints — registry Run-key entries, scheduled tasks, service installations, DLL search-order hijacks, and (in later variants) WMI event-subscription persistence; the family rotates persistence mechanisms across builds, so defenders should monitor the combination of Windows persistence surfaces rather than rely on any single mechanism.
  • C2-protocol fingerprints — HTTPS-over-port-443 with custom encryption / obfuscation; operator-infrastructure rotation patterns documented by Kaspersky and ESET; in some variants blockchain-based or steganography-based command-channel patterns.
  • Anti-analysis fingerprints — anti-VM checks, anti-debugging routines, control-flow obfuscation, encrypted-string handling, sandbox-detection logic; the presence of layered anti-analysis is itself a fingerprint distinguishing Manuscrypt from commodity malware that typically uses one or two of these techniques rather than the full stack.
  • Behavioral signatures from CTI vendors — Kaspersky (foundational Manuscrypt detections), ESET (continued coverage of updated builds), AhnLab (Korea-specific detections including ASEC reporting on Korean-exchange-targeted variants), CrowdStrike (Hidden Cobra / Lazarus-family rules), Microsoft (Diamond Sleet / Onyx Sleet rules in Defender for Endpoint covering related Lazarus Windows tooling), Mandiant (TEMP.Hermit-cluster rules).
  • external cyber-threat-intel taxonomy S0259 — the canonical software-entry reference; cross-framework anchor for Manuscrypt-tracking detection content.

Note: omit specific file hashes; consume current IOCs from CTI-vendor feeds and from external cyber-threat-intel taxonomy S0259's external-reference list.

Citations

  • [mandiantcoincheck2018] — Mandiant / industry post-mortem coverage of the January 2018 Coincheck exchange compromise; Manuscrypt-family Windows tooling reported.
  • [chainalysiskucoinlazarus] — Chainalysis wallet-cluster attribution of the September 2020 KuCoin hack to Lazarus; the post-compromise on-chain side of the case.
  • [chainalysis2024dprk] — DPRK-attributed cryptocurrency-theft scale companion citation.

Discussion

On family-naming caveats. The Manuscrypt / KEYMARBLE / FALLCHILL / NukeSped / Volgmer naming surface is unusually noisy for an industry-tracked family. KEYMARBLE was the NCCIC / US-CERT 2018 catalogue naming for a component or variant that overlaps with later-named Manuscrypt builds; FALLCHILL and Volgmer are related-but-distinct earlier Lazarus Windows backdoors with documented code overlap that has caused some catalogues to fold them under the Manuscrypt label and others to keep them separate. For OAK purposes the consolidating principle is the multi-stage Lazarus Windows backdoor family with the long evolution lineage; defenders should consume the family under whichever vendor-specific naming their CTI feeds use and recognise the cross-vendor convergence on external cyber-threat-intel taxonomy S0259 as the canonical anchor.

On lineage and ecosystem position. Manuscrypt is the Windows persistence layer of the DPRK-against-crypto-industry intrusion tradecraft. Its role is downstream of the macOS-side AppleJeus (OAK-S09) and TraderTraitor (OAK-S08) initial-access lineage and upstream of the on-chain extraction Tactics that produce the final theft. The 2017–2019 pre-DeFi era saw Manuscrypt in a more dominant entry-vector role (direct-phish payload delivery into Windows victim environments at exchanges); the post-2022 era sees Manuscrypt staged downstream of macOS-initial-access vectors when the victim environment includes Windows workstations (as most crypto-firm environments do). The family's continuing service is itself notable — most state-sponsored backdoor families have shorter operational lifetimes before being replaced; Manuscrypt's ten-plus-year continuity reflects DPRK operator preference for incremental evolution over wholesale replacement.

On attribution caveats. Cluster-level attribution to DPRK / Lazarus is confirmed via U.S. CERT advisories, FBI public statements, and sustained multi-vendor industry-forensic corroboration. Per-incident attribution that a specific compromise used Manuscrypt as the persistence layer is in many cases inferred-strong — public post-mortems often document the attribution to Lazarus at cluster level without family-naming the specific Windows backdoor used. Defenders should treat the family as a near-default expectation in DPRK-attributed Windows-environment crypto-firm intrusions in the 2017–2024 window and consume detection content accordingly.

On evolution. Manuscrypt's evolution proceeds through incremental anti-analysis layering and C2-protocol obfuscation rather than through wholesale rewrites; the 2024 builds are recognisably continuous with the 2017 builds in module structure and persistence-mechanism preferences. Defenders should not assume that absence of a known-hash match means absence of family — the per-victim build customisation that defeats hash-only detection is itself part of the family's tradecraft, and behavioral / process-tree-pattern detection is more robust than IOC-based detection at this lineage's continuity scale.

Techniques observed (2)

Used by