SIGNBT is a Windows backdoor associated with Lazarus Group operations, particularly campaigns targeting South Korean organizations through watering-hole attacks and exploitation of vulnerabilities in locally deployed financial-security and enterprise software. It has been observed as an initial in-memory implant and as a follow-on payload loader, with multiple versions documented across related intrusion clusters. In some reporting, later variants are mapped to the malware name Struggle.
SIGNBT has been used in espionage-focused intrusions to establish covert access, execute remote commands, conduct internal reconnaissance, steal files, inject code into legitimate processes, and retrieve or execute additional payloads. Observed tradecraft includes fileless or memory-resident execution, in-memory decryption of later stages, encrypted configuration or data storage in the Windows registry, and use of TLS callbacks as an anti-analysis and evasion mechanism. Some variants have been executed inside legitimate Windows processes, including SyncHost.exe and svchost.exe, to blend with normal activity and support stealthy post-compromise operations.
Delivery has been tied at high confidence to watering-hole compromises of legitimate websites visited by intended victims, where malicious scripts exploited vulnerable South Korean security software without requiring a conventional download prompt. Related campaigns also used spearphishing lures such as resumes, recruiting approaches, investment material, and industry surveys, although reporting does not always establish which payload was delivered in each case. SIGNBT has appeared alongside other Lazarus tooling including COPPERHEDGE, ThreatNeedle, wAgent, Agamemnon, and LPEClient, and overlaps in malware lineage and operator tradecraft support its association with Lazarus. Victims have included organizations in software, IT, finance, telecommunications, semiconductor manufacturing, healthcare, education, manufacturing, and other South Korean sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or user-initiated download. | The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in the watering-hole campaign to provide remote command execution, file theft, internal reconnaissance, process injection, and delivery of additional payloads. Reports also describe DLL side-loading, encrypted registry blobs, and in-memory PE loading across SIGNBT clusters.
Named malware cluster referenced in a post linking to an analysis by S2W; the post indicates it is fileless malware.
Referenced as a Lazarus malware/tool family associated with TLS callback anti-analysis and custom cryptography tradecraft.
SIGNBT is referenced as a Lazarus tool family exhibiting similar TLS callback anti-analysis behavior to the analyzed loader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.