BLUELIGHT is a backdoor/reconnaissance malware associated with the North Korea-linked APT37/ScarCruft/Vedalia espionage group. It has been described as a second-stage payload and as a basic reconnaissance tool used in previous APT37 campaigns, including as part of a multistage 2021 watering-hole attack against a South Korean online newspaper involving an Internet Explorer exploit. In later reporting on APT37’s 2025 Ruby Jumper campaign, BLUELIGHT was again observed as a previously attributed backdoor used alongside other tooling.
High-confidence capabilities described in the source material include collecting the username from a compromised host; enumerating installed anti-virus products; collecting passwords stored in Internet Explorer, Edge, Chrome, and Naver Whale; harvesting cookies from Internet Explorer, Edge, Chrome, and Naver Whale; enumerating files and associated metadata; capturing screenshots every 30 seconds for the first 5 minutes after initiating a C2 loop and then every five minutes thereafter; zipping files before exfiltration; exfiltrating data over its C2 channel; and uninstalling itself.
BLUELIGHT uses legitimate cloud services/providers for command and control. Reporting states it can communicate with several different cloud services, and specific later reporting ties it to Microsoft OneDrive via the Microsoft Graph API as well as legitimate cloud providers including Google Drive, Microsoft OneDrive, pCloud, and BackBlaze. In APT37 operations, BLUELIGHT has also been used to launch Dolphin’s Python loader on compromised systems, while Dolphin provided broader espionage functionality.
The malware is linked to espionage activity primarily aligned with APT37 targeting, including South Korean and journalist-focused operations. Stairwell assessed Goldbackdoor as a successor to BLUELIGHT, and other reporting described Goldbackdoor as a variant/successor of the BlueLight malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The backdoor was used as the final payload of a multistage attack in early 2021, involving a watering-hole attack on a South Korean online newspaper, an Internet Explorer exploit, and another ScarCruft backdoor, named BLUELIGHT. | ScarCruft exploits CVE-2020-1380 to compromise victims.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stairwell found a new malware sample named “Goldbackdoor,” which was assessed as a successor of “Bluelight.”
The first known usage was by the North Korea-linked Vedalia espionage group (aka APT37), which developed Bluelight, a second-stage payload that could communicate with several different cloud services for C&C purposes.
BLUELIGHT can harvest cookies from Internet Explorer, Edge, Chrome, and Naver Whale browsers.
...and finally to BLUELIGHT and FOOTWINE for full surveillance.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes adversaries using Base64, XOR, RC4, AES, hexadecimal encoding, string encryption, code flattening, custom crypters, and other obfuscation methods to hide payloads, strings, configuration data, URLs, and scripts.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Multiple malware and threat groups are described as collecting/deriving local system time, date, timestamp, tick count, or time zone (e.g., "used time /t and net time \ip/hostname for system time discovery"; "collects the timestamp from the victim’s machine"; "can collect the time zone information from the system").
"Agent Tesla can capture screenshots of the victim’s desktop"; "AppleSeed can take screenshots on a compromised host"; "APT28 has used tools to take screenshots from victims"; "Cobalt Strike's Beacon payload is capable of capturing screenshots"; "PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals"; "Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop"
"AppleSeed has compressed collected data before exfiltration."; "APT28 used a publicly available tool to gather and compress multiple documents..."; "Aria-body has used ZIP to compress data..."; "Cadelspy...compress stolen data into a .cab file."; "Daserf hides collected data in password-protected .rar archives."; "FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration."; "Lazarus Group has compressed exfiltrated data with RAR...archive specified directories in .zip format"; "XCSSET will compress entire ~/Desktop folders..."
Several entries describe broader use of HTTP/HTTPS and related web mechanisms for C2, including "Crutch has conducted C2 communications with a Dropbox account using the HTTP API," "BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API," and "Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously attributed backdoor that uses legitimate cloud services (Google Drive, OneDrive) as part of its operations (e.g., for C2 or data exchange).
Cloud-C2 backdoor that abuses legitimate cloud storage providers (e.g., Google Drive, Microsoft OneDrive, pCloud, BackBlaze) to execute commands, enumerate files, transfer payloads/files, and self-remove.
A late-stage surveillance component used alongside FOOTWINE to enable monitoring of compromised systems (details not further described in the content).
Full-featured backdoor previously associated with APT37 and observed as part of the RubyJumper campaign; used as an attribution indicator in the reporting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.