ThreatNeedle is a Windows backdoor associated with the Lazarus Group and tracked since at least 2018. It has been used in espionage operations with a strong focus on South Korean targets and the defense sector, and has also appeared in broader Lazarus intrusion clusters alongside tooling such as wAgent, SIGNBT, COPPERHEDGE, and Agamemnon. Reported victim sectors include defense, software, IT, financial services, semiconductor manufacturing, telecommunications, and other South Korean industrial organizations.
ThreatNeedle is designed for in-memory execution and post-compromise control. Observed capabilities include collecting files and data from compromised hosts, executing commands, and operating as a full-featured backdoor. In more recent Lazarus activity, a ThreatNeedle variant was split into loader and core components, with the core implementing dozens of commands. The malware has been observed storing encrypted configuration data in the Windows Registry and, in newer variants, using modern encrypted command-and-control communications.
Persistence and stealth are notable characteristics. ThreatNeedle has been observed registering payloads as Windows services and running in memory. It can store RC4-encrypted configuration data in the Registry, and later variants have used service-related masquerading and other service-based persistence approaches. In Operation SyncHole, Lazarus used a ThreatNeedle variant injected into a legitimate process associated with South Korean software, consistent with a defense-evasion and process-injection workflow.
Delivery has included spearphishing emails carrying malicious Word documents that required user interaction for initial execution. ThreatNeedle has also been linked to watering-hole operations exploiting vulnerabilities in widely deployed South Korean software, where malicious scripts ultimately launched a legitimate process and injected shellcode to load the backdoor in memory. These campaigns demonstrate both social-engineering-based and exploit-assisted initial access paths.
ThreatNeedle is best characterized as a Lazarus backdoor used for long-term access, intelligence collection, and follow-on payload delivery in targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This address is also included in a Kaspersky report on Lazarus threat actors’ attack cases targeting the defense industry using ThreatNeedle.
“In its more recent campaigns it has started deploying a new malware we call ThreatNeedle.”
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware being delivered through phishing or spearphishing emails containing malicious attachments such as Microsoft Office documents, PDFs, RAR/ZIP archives, CHM, ISO, IMG, HTA, LNK, and executable files disguised as documents.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples include: “ComRAT has encrypted and stored its orchestrator code in the Registry…”, “ShadowPad maintains a configuration block and virtual file system in the Registry.”, and “QakBot can store its configuration information…under HKCU\Software\Microsoft.”
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
RedCurl mimicked legitimate file names and scheduled tasks, e.g. MicrosoftCurrentupdatesCheck and MdMMaintenenceTask to mask malicious files and scheduled tasks.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
"LPEClient is a tool known for victim profiling and payload delivery (T1105)..."; "...Innorix abuser is used for lateral movement. It is downloaded by the Agamemnon downloader (T1105)..."
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as Lazarus-associated malware in a comparison of overlapping infrastructure; no direct role in the main Xctdoor campaign described here.
Malware used in Lazarus Group's Operation SyncHole targeting South Korean firms; details not provided in the excerpt.
ThreatNeedle is a remote access trojan/backdoor used by the Lazarus group for espionage, lateral movement, and data exfiltration in targeted attacks, often as part of multi-stage campaigns.
Lazarus backdoor used as an initial implant; in this campaign it is delivered via watering-hole + suspected Cross EX exploitation, injected into SyncHost.exe, supports encrypted C2 (Curve25519 key exchange + ChaCha20), and can establish persistence via service/SSP-related mechanisms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.