Volgmer - Comprehensive Threat Intelligence Report

2017-11-14 Bloo

https://bloo.io/research/malware/volgmer

Thumbnail for Volgmer - Comprehensive Threat Intelligence Report

Volgmer is a Windows backdoor attributed in the source to North Korea's Lazarus Group, also known as Hidden Cobra, and described as active from at least 2013-2014 through later campaigns. It installs as a legitimate-looking service with a random name, stores encrypted configuration in the registry, tampers with timestamps, and gives operators remote control for system discovery, file transfer, process execution, and command execution. The source says Volgmer used custom C2 communications over ports such as 8080 and 8088, sometimes with SSL or web-like requests using a misspelled "Mozillar" user agent. Reported targeting spans South Korea and later global government, military, financial, critical infrastructure, defense, high-tech, and related sectors, making it relevant to long-running Lazarus espionage and foothold operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7f953c6988d829c9c4ac2002572c9055 2017-11-14 2023-10-13
HASH ea5d322648ff108b1c9cbdd1ef4a5959 2017-11-14 2023-10-13
HASH b1225fa644eebafba07f0f5e404bd4fd 2017-11-14 2023-10-13
HASH 64965a88e819fb93dbabafc4e3ad7b6c 2017-11-14 2023-10-13
HASH 3e6119ebfacd1d88acbd2ca460c70b49 2017-11-14 2023-10-13
HASH c2ab2a8ffdc18c24080e889a634ef279 2017-11-14 2023-10-13
HASH 72756e6ebb8274d9352d8d1e7e505906 2017-11-14 2023-10-13
HASH 570a4253ae80ee8c2b6b23386e273f3a 2017-11-14 2023-10-13
HASH 5473fa2c5823fbab2b94e8d5c44bc7b4 2017-11-14 2023-10-13
HASH cf2ff5b59c638a06d8b81159b9a435ea 2017-11-14 2023-10-13
HASH 44fa8daa347ef5dd107bf123b4688797 2017-11-14 2023-10-13
HASH 5c87373eef090bed525b80aef398ee8a 2017-11-14 2023-10-13
HASH a545f548b09fdf61405f5cc07e4a7fa1 2017-11-14 2023-10-13
HASH 226cc1f17c4625837b37b5976acbd68e 2017-11-14 2023-10-13
HASH 1e2acecce7b5e9045b07d65e9e8afe1f 2017-11-14 2023-10-13
HASH 9a87f19609f28d7f7d76f9759864bd08 2017-11-14 2023-10-13
HASH 1ecd83ee7e4cfc8fed7ceb998e75b996 2017-11-14 2023-10-13
HASH fe32303e69b201f9934248cc06b32ef8 2017-11-14 2023-10-13
HASH 17eacf4b4ae2ca4b07672dcc12e4d66d 2017-11-14 2023-10-13
HASH 0171c4a0a53188fe6f9c3dfcc5722be6 2017-11-14 2023-10-13
HASH 6da7d8aec65436e1350f1c0dfc4016b7 2017-11-14 2023-10-13
HASH 35f9cfe5110471a82e330d904c97466a 2017-11-14 2023-10-13
HASH 85b6e4ea8707149b48e41454cbd0d5ad 2017-11-14 2023-10-13
HASH eb9db98914207815d763e2e5cfbe96b9 2017-11-14 2023-10-13
HASH 693afaedf740492df2a09dfcc08a3dff 2017-11-14 2023-10-13
HASH e3d03829cbec1a8cca56c6ae730ba9a8 2017-11-14 2023-10-13
HASH e273803ae6724a714b970dd86ca1acd0 2017-11-14 2023-10-13
HASH d52b5d8c20964333f79ff1bce3385d0b 2017-11-14 2023-10-13
HASH 6e21cc6669ada41e48b369b64ec5f37b 2017-11-14 2023-10-13
HASH 8b3ec4b9c7ad20af418e89ca6066a3ad 2017-11-14 2023-10-13
HASH 4753679cef5162000233d69330208420 2017-11-14 2023-10-13
HASH 5dd1ccc8fb2a5615bf5656721339efed 2017-11-14 2023-10-13
HASH 947124467bd04b7624d9b31e02b5ee7f 2017-11-14 2023-10-13
HASH 9a5fa5c5f3915b2297a1c379be9979f0 2017-05-22 2023-10-13
HASH eff3e37d0406c818e3430068d90e7ed… 2017-11-14 2020-03-09
HASH e40a46e95ef792cf20d5c14a9ad0b3a… 2017-11-14 2020-03-09
HASH ff2eb800ff16745fc13c216ff6d5cc2… 2017-11-14 2020-03-09
HASH fee0081df5ca6a21953f3a633f2f64b… 2017-11-14 2020-03-09
HASH 1d0999ba3217cbdb0cc85403ef75587… 2017-11-14 2020-03-09
HASH 6dae368eecbcc10266bba32776c40d9… 2017-11-14 2020-03-09
HASH 9f177a6fb4ea5af876ef8a0bf954e37… 2017-05-22 2020-03-09
IPv4 120.234.15.199 2017-11-14 2017-11-14
IPv4 148.97.97.195 2017-11-14 2017-11-14
IPv4 157.204.231.83 2017-11-14 2017-11-14
IPv4 20.9.116.186 2017-11-14 2017-11-14
IPv4 97.71.67.186 2017-11-14 2017-11-14
IPv4 194.244.28.113 2017-11-14 2017-11-14
IPv4 42.188.190.89 2017-11-14 2017-11-14
IPv4 130.176.242.24 2017-11-14 2017-11-14
IPv4 70.190.93.78 2017-11-14 2017-11-14
IPv4 99.222.131.203 2017-11-14 2017-11-14
IPv4 35.223.16.103 2017-11-14 2017-11-14
IPv4 133.69.42.200 2017-11-14 2017-11-14
IPv4 218.224.232.84 2017-11-14 2017-11-14
IPv4 179.145.48.116 2017-11-14 2017-11-14
IPv4 172.198.149.186 2017-11-14 2017-11-14
IPv4 181.87.187.210 2017-11-14 2017-11-14

Related Actors

Related Reports

2025-08-13 • 50% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1218.010 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1573 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004
Shares tags: Lazarus, T1082, T1059.003
2021-12-02 • 49% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1573.001 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004 #T0865
Shares tags: Lazarus, T1082, T1059.003
2024-07-19 • 43% Match
#Trend #Andariel #Kimsuky #MoonstoneSleet #Lazarus #T1082 #T1059.003 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1555 #T1560 #T1071.001 #T1046 #T1112 #T1115 #T1083 #T1497 #T1056.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1071 #T1124 #T1222 #T1552 #T1057 #T1583.003 #T1518.001 #T1547.001 #T1053.005 #T1539 #T1608.005 #T1583.001 #T1059.001 #T1053 #T1552.001 #T1566 #T1059 #T1003 #T1497.001 #T1102.001 #T1574.002 #T1562.001 #T1490 #T1486 #T1129 #T1133 #T1571 #T1548 #T1190 #T1203 #T1564.001 #T1087 #T1562.004 #T1218.011 #T1070.006 #T1547 #T1068 #T1614 #T1573 #T1095 #T1562 #T1070 #T1047 #T1056 #T1176 #T1010 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1202 #T1087.002 #T1021.004 #T1222.001 #T1518 #T1564.003 #T1505.003 #T1069.002 #T1564 #T1595.002 #T1027.005 #T1070.001 #T1056.004 #T1584
Shares tags: Lazarus, T1082, T1059.003
2025-08-25 • 42% Match
#Lazarus #GolangGhost #T1059.003 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1071.001 #T1115 #T1083 #T1056.001 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1547.001 #T1059.001 #T1497.001 #T1219 #T1574.002 #T1562.001 #T1622 #T1027.002 #T1573.001 #T1190 #T1123 #T1132.002 #T1564.001 #T1548.002 #T1055.012 #T1027.007 #T1217 #T1106 #T1027.009 #T1036.003 #T1055.002 #T1036.007 #T1059.010 #T1136.001 #T1134.004 #T1614.001 #T1574.007 #T1098.007 #T1010 #T1071.004 #T1021.002 #T1021.006
Shares tags: Lazarus, T1059.003, T1005 • Same author: Bloo
« Back