WinorDLL64: A backdoor from the vast Lazarus arsenal?

2023-02-23 ESET

https://www.welivesecurity.com/2023/02/23/winordll64-backdoor-vast-lazarus-arsenal/

Thumbnail for WinorDLL64: A backdoor from the vast Lazarus arsenal?

ESET identified WinorDLL64 as a Wslink payload and assessed with low confidence that it is connected to Lazarus based on South Korean victim telemetry, timing, development-environment overlap, and behavior/code similarities with GhostSecret and Bankshot-related samples. WinorDLL64 is a backdoor loaded by the Wslink server-style loader and uses an already established encrypted communication context to collect system information, manipulate files, execute commands, and support operator control. The analysis highlights overlaps such as process listing, directory and volume enumeration, file read/write and exfiltration, secure file deletion, process termination, and system-information collection. Supporting infrastructure and tooling evidence includes use of MemoryModule, Oreans Code Virtualizer in the loader, AES-CBC protected communications, and command functionality such as PowerShell execution, directory compression/download, session listing, and connection timing. The finding matters because it adds a concrete Wslink payload to the Lazarus toolset with enough technical detail for defenders to hunt related loader-payload combinations while preserving the report's low-confidence attribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 70de783e5d48c6fbb576bc494baf063… 2023-02-23 2023-02-23
HASH 1ba443fde984cee85ebd4d4fa7eb126… 2023-02-23 2023-02-23
HASH 8ec9219303953396e1cb7105cdb18ed… 2023-02-23 2023-02-23
HASH fe887fcab66d7d7f79f05e0266c0649… 2018-04-24 2023-02-23

Related Reports

2023-02-02 • 39% Match
#Whitepaper #NoPineapple #DTrack #GREASE #Zimbra #T1082 #T1119 #T1070.004 #T1041 #T1560 #T1071.001 #T1083 #T1071 #T1057 #T1053.005 #T1036.005 #T1059 #T1078 #T1190 #T1049 #T1016 #T1018 #T1003.001 #T1021.001 #T1106 #T1090.001 #T1074 #T1553 #T1033 #T1569.002 #T1090.002 #T1012 #T1087.002 #T1114.002 #T1505.003 #T1556 #T1037.005 #T1136 #T1070.007 #T1587.002
Shares tags: T1082, T1070.004, T1083 • Published within a month
2025-08-13 • 30% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1218.010 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1573 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004
Shares tags: T1082, T1005, T1070.004
2021-12-02 • 30% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1573.001 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004 #T0865
Shares tags: T1082, T1005, T1070.004
2025-02-20 • 23% Match
#BeaverTail #InvisibleFerret #DeceptiveDevelopment #T1027.013 #T1082 #T1119 #T1059.003 #T1140 #T1005 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1115 #T1083 #T1056.001 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1555.003 #T1124 #T1583.003 #T1552.001 #T1585.001 #T1219 #T1133 #T1571 #T1564.001 #T1016 #T1074.001 #T1657 #T1071.002 #T1021.001 #T1614 #T1555.001 #T1217 #T1095 #T1025 #T1010 #T1560.002 #T1030 #T1567.004 #T1564.003
Shares tags: T1082, T1005, T1587.001 • Same author: ESET
« Back