wAgent is a Lazarus-associated Windows malware family used in targeted intrusions as part of broader post-compromise operations. It has been observed in campaigns linked to the North Korean Lazarus Group, including TraderTraitor activity and the Operation SyncHole intrusion set targeting South Korean organizations. In the latter campaign, wAgent appeared alongside other Lazarus tooling such as ThreatNeedle, Agamemnon, SIGNBT, and COPPERHEDGE.
In Operation SyncHole, a wAgent loader was disguised as a DLL and executed through rundll32, then decrypted and launched an embedded payload using AES-128-CBC. The malware supported command-and-control communications using form-data or JSON and incorporated RSA-related functionality via the GNU Multiple-Precision library. A reported variant also contained logic related to a next-auth session token key, indicating interest in theft or abuse of web session material. Its observed role in Lazarus operations is consistent with use as a backdoor or loader-stage implant enabling follow-on access and operator tasking.
wAgent has been deployed in intrusion chains that relied on watering-hole attacks and exploitation of vulnerabilities in widely deployed South Korean software, with execution occurring inside or alongside legitimate processes to reduce detection. The malware is associated with espionage- and financially motivated Lazarus activity and has been used against organizations in sectors including software, IT, finance, semiconductor manufacturing, and telecommunications. Its reuse across Lazarus operations indicates it is part of the group’s established malware ecosystem for stealthy access and post-exploitation on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Known Lazarus backdoor referenced as reused in TraderTraitor activity.
wAgent is a backdoor used by the Lazarus group for persistent access and control over compromised systems, often deployed in watering hole and supply chain attacks.
Lazarus-associated downloader/loader; in this campaign it is executed via DLL side-loading style execution (rundll32), decrypts an on-disk payload (AES-128-CBC) and communicates with C2 using form-data or JSON, supporting plugin delivery and in-memory loading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.