DYEPACK is a Lazarus-linked malware framework associated most closely with APT38 and Bluenoroff, North Korean threat clusters focused on financially motivated intrusions. It has been described as part of a SWIFT-focused money-laundering and bank-heist toolset used in operations against financial institutions connected to international payment systems. Public reporting links DYEPACK to attacks in which operators created, deleted, and altered records in databases used for SWIFT transactions, indicating a role in manipulating stored financial data to facilitate fraudulent transfers and hinder detection or reconciliation.
DYEPACK appears in the broader post-compromise arsenal used by Lazarus financial operators alongside other backdoors, credential theft tools, and passive listeners. Its documented use is consistent with post-exploitation activity inside compromised banking environments rather than commodity crimeware deployment. The malware has been associated with campaigns aimed at emptying SWIFT-connected banking servers and supporting fraudulent transaction workflows. This places it within the operational ecosystem used by APT38 to monetize intrusions into banks and related financial infrastructure.
The malware is primarily associated with Windows-centric enterprise intrusions conducted by Lazarus subgroups against banks and other financial entities. While Lazarus broadly uses spearphishing, watering holes, brute force, and exploitation for initial access, the high-confidence reporting specific to DYEPACK centers on its use after compromise for manipulation of SWIFT-related database records and related financial theft operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT38 Bitsran BLINDTOAD BOOTWRECK Contopee DarkComet DYEPACK HOTWAX NESTEGG PowerRatankba REDSHAWL WORMHOLE Lazarus Group
APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions.
Their collection of post-exploitation backdoors has included the msoRAT credential stealer, the SWIFT money laundering framework DYEPACK, and various passive backdoors and virtual "listeners" for receiving and processing data from target machines.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family associated with BlueNorOff operations.
A SWIFT money laundering framework used by TA444 in post-exploitation activity.
Post-exploitation backdoor used by TA444 historically.
Malware linked to SWIFT banking attacks and Lazarus/APT38 financial operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.