⤷ Title: Lazarus Group’s New ScoringMathTea RAT Uses Reflective Plugin Loader and Custom Polyalphabetic Crypto for Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:39:19 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #cyber_espionage #Lazarus Group #Polyalphabetic Cipher #rat #Reflective DLL Injection #ScoringMathTea #TEA/XTEA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:39:19 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #cyber_espionage #Lazarus Group #Polyalphabetic Cipher #rat #Reflective DLL Injection #ScoringMathTea #TEA/XTEA
Daily CyberSecurity
Lazarus Group's New ScoringMathTea RAT Uses Reflective Plugin Loader and Custom Polyalphabetic Crypto for Espionage
A deep-dive on Lazarus’s ScoringMathTea RAT reveals a full reflective DLL injection system, TEA/XTEA C2 encryption, and a polyalphabetic cipher for API hashing—a highly evasive tool for espionage.