SierraBravo-Two is a Lazarus Group malware family. The provided content specifically attributes to it an SMTP-based notification/exfiltration function: it generates an email message containing information about newly infected victims. Within the broader Lazarus malware ecosystem, it is listed alongside tools such as SierraAlfa, SierraCharlie, SHARPKNOT, KiloAlfa, IndiaIndia, Sumarta, Torisma, and DRATzarus. High-confidence information in the source ties SierraBravo-Two to Lazarus Group operations and indicates its use of SMTP as a channel for transmitting victim infection information. No additional platform details, infection vector, or industry targeting are directly provided for SierraBravo-Two itself beyond its association with Lazarus Group campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus malware that exfiltrates infection information by generating SMTP email messages about newly infected victims.
Malware that generates SMTP email messages containing information about newly infected victims for exfiltration or notification.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.