The Lazarus Injector

2019-07-22 Norfolk

https://norfolkinfosec.com/the-lazarus-injector/

Thumbnail for The Lazarus Injector

The Lazarus Injector analysis covers a DPRK SWIFT-heist-related tool used to load a supplied payload into explorer.exe. The injector validates command-line parameters and payload file access, enumerates processes to locate Explorer, allocates remote memory, writes the payload, and starts execution through resolved APIs. Optional parameters control sleep and cleanup behavior, including overwriting and deleting the original payload from disk. The report provides hashes and behavioral details useful for detecting Lazarus loader activity rather than relying on a long indicator list alone.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b9ad0cc2a2e0f513ce716cdf037da907 2019-07-22 2020-08-05
HASH db0f102af2d350aa1a63772e6ee9b21… 2019-07-22 2019-07-22
HASH 1a50a7ea5ca105df504c33af1c0329d… 2019-07-22 2019-07-22

Related Actors

Related Reports

« Back