The Lazarus Injector
2019-07-22 • Norfolk •
The Lazarus Injector analysis covers a DPRK SWIFT-heist-related tool used to load a supplied payload into explorer.exe. The injector validates command-line parameters and payload file access, enumerates processes to locate Explorer, allocates remote memory, writes the payload, and starts execution through resolved APIs. Optional parameters control sleep and cleanup behavior, including overwriting and deleting the original payload from disk. The report provides hashes and behavioral details useful for detecting Lazarus loader activity rather than relying on a long indicator list alone.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b9ad0cc2a2e0f513ce716cdf037da907 | 2019-07-22 | 2020-08-05 |
| HASH | db0f102af2d350aa1a63772e6ee9b21… | 2019-07-22 | 2019-07-22 |
| HASH | 1a50a7ea5ca105df504c33af1c0329d… | 2019-07-22 | 2019-07-22 |
Related Actors
Related Reports
Shares tag: Lazarus • Same author: Norfolk
Shares tag: Lazarus • Published within a week
Shares tag: Lazarus • Published within a week
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month