MATA is a modular, multi-platform malware framework associated with Lazarus and used in long-running espionage and financially motivated intrusions since at least 2018. It has been observed targeting commercial enterprises, defense contractors, industrial organizations, and network-oriented environments, including activity against entities in Eastern Europe as well as earlier operations affecting organizations in Asia and Europe. Security vendors have also referred to parts of this framework as Dacls.
The framework is notable for its breadth of platform support and modular design. Documented variants run on Windows and Linux, and a macOS variant has also been identified. Linux samples have been assessed as suitable for network equipment or server-side deployment, and later campaigns included Linux backdoors distributed through compromised enterprise security management infrastructure. MATA has evolved through multiple generations featuring loaders, validators, backdoors, orchestrators, and plug-ins, with newer generations rewritten or substantially redesigned while preserving core operational concepts such as encrypted configuration, flexible communications, and plugin-based tasking.
Observed MATA capabilities include victim profiling, remote command execution, file upload and download, process execution, network reconnaissance, proxying, code injection, monitoring, and extensive post-compromise control. Some generations support active and passive command-and-control modes, stacked transport and proxy protocols, and internal proxy chaining across multiple compromised hosts, enabling operators to traverse segmented environments. Campaigns linked to MATA also deployed dedicated stealing components that captured credentials, browser data, cookies, screenshots, clipboard contents, and keystrokes.
MATA has been used after targeted initial access, including spearphishing with exploit-bearing documents and malicious download links. In one major campaign active from 2022 to 2023, operators used spearphishing documents exploiting CVE-2021-26411, multi-stage loaders, validation modules, Windows and Linux backdoors, and a removable-media component designed to exchange encrypted tasking and results across air-gapped networks. The same campaign showed extensive lateral movement through compromised domain controllers and abuse of security compliance and endpoint protection management systems to deploy MATA broadly across Windows and Linux hosts.
Operators using MATA have also paired it with privilege-escalation and defense-evasion tooling, including public exploit code for CVE-2021-40449 and BYOVD-style techniques to impair endpoint monitoring. The framework has additionally appeared in ransomware-related intrusions linked to Lazarus, including incidents where a MATA backdoor preceded enterprise-wide deployment of VHD ransomware. Overall, MATA is best characterized as a mature cross-platform backdoor framework for stealthy post-compromise operations, lateral movement, reconnaissance, credential and data theft, and sustained access in high-value enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
It seems the actor utilized the public CVE-2021-40449 exploit, which we discovered and reported in 2021. Publicly available code called CallbackHell was used by this malware to elevate privileges and write into the kernel's memory; The malware triggers the CVE-2021-40449 vulnerability, a use-after-free vulnerability, in Win32k’s NtGdiResetDC API.
According to our analysis, the fetched HTML page contains a CVE-2021-26411 exploit which was previously used by the Lazarus group in their campaign against security researchers.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In early September 2022 Kaspersky experts discovered several detections of malware from the MATA cluster, previously attributed to the Lazarus group, compromising defense contractor companies in Eastern Europe.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
In this instance, we believe initial access was achieved through opportunistic exploitation of a vulnerable VPN gateway.
Additionally, we found another victim within the same corporation compromised by the MATA malware, although executed via Windows task scheduler.
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive malware framework described as the delivery mechanism for VHD ransomware and attributed in the article to North Korean operators.
A multi-stage, modular backdoor platform attributed in prior reporting to Lazarus, used for targeted intrusions. It supports multiple C2 protocols (e.g., TCP/UDP/SSL/DTLS variants), complex proxy chaining inside victim networks, plugin/module-based command execution (file/process/net recon/proxy/inject/monitoring), and includes Windows and Linux variants. Later generations (gen4/gen5) show major rewrites, richer protocol stacks, IPC-based internal architecture (gen5), and capabilities to operate in constrained/segmented environments (including proxy chains and air-gapped support via related USB module).
Modular Lazarus-linked malware framework/backdoor with multi-stage delivery; includes variants for Linux and capabilities for proxy chaining and complex C2 communications.
A modular malware framework historically used by Lazarus, referenced for comparison with newer tooling in this campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.