Agamemnon downloader is a Lazarus Group malware component observed in Operation SyncHole, a campaign active from at least November 2024 to February/March 2025 targeting South Korean organizations. In that campaign, Lazarus targeted sectors including software, IT, financial services, semiconductor manufacturing, and telecommunications, using watering-hole attacks and exploitation of vulnerabilities in South Korean software such as Cross EX and Innorix Agent. Agamemnon downloader was one of the malware families deployed alongside ThreatNeedle, wAgent, SIGNBT, and COPPERHEDGE.
Its documented role is to download and execute additional payloads received from the C2 server. It can execute payloads either through reflective loading or via the open-source Tartarus-TpAllocInject technique based on Tartarus' Gate/Halo's Gate/Hell's Gate concepts. The malware was also used to deliver an Innorix abuser for lateral movement. That Innorix-related component exploited environments running Innorix Agent version 9.2.18.496, enabling internal hosts to download further malware due to insufficient traffic validation, and was used to drop a legitimate AppVShNotify.exe together with a malicious USERENV.dll for DLL sideloading.
High-confidence associations in the provided content tie Agamemnon downloader to Lazarus Group activity focused on South Korean environments and to post-compromise payload delivery and execution. No standalone indicators of compromise specific to Agamemnon downloader were provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware and Tools: ThreatNeedle, wAgent, Agamemnon downloader, SIGNBT, COPPERHEDGE.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Agamemnon downloader is a malware component used by Lazarus to download and execute additional payloads on compromised systems as part of multi-stage attacks.
Downloader that parses C2 commands/parameters delimited by ';;' and executes delivered payloads either via reflective loading or via the Tartarus-TpAllocInject technique; also used to fetch the Innorix Agent abuser for lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.