Comebacker is a Lazarus-linked custom backdoor and loader, also described in the content as a Diamond Sleet-linked backdoor/loader and in one report as a dangerous trojan delivered through malicious Python and npm packages. It has been observed in multiple North Korea-associated intrusion sets and is repeatedly described as exclusively associated with Lazarus, although some reporting notes overlap with Diamond Sleet/Pompilus and uncertainty about the exact Lazarus subgroup responsible in some campaigns.
The malware has been used alongside other Lazarus tooling including BLINDINGCAN, InfoHook, ChromeStealer, RP_Proxy, Mimikatz, Curl, and Medusa ransomware. Multiple reports state that BLINDINGCAN has been used in conjunction with Comebacker, and one report describes a new Comebacker variant leading to deployment of a new BLINDINGCAN remote access trojan variant. In current ransomware and extortion campaigns attributed to Lazarus, Comebacker was part of a broader toolset used before ransomware deployment to maintain access and support follow-on activity.
Observed delivery and infection vectors in the content include embedding Comebacker in seemingly innocuous Python and npm packages, including malicious PyPI packages downloaded by developers onto Windows systems. Microsoft reporting cited in the content states Lazarus used Comebacker in February by embedding it in Python and npm packages to establish contact with a command-and-control server and retrieve additional payloads. Another report says developers tricked into downloading malicious software packages on Windows were infected with Comebacker.
Technical behavior directly described in the content includes variants observed as both a DLL and EXE, command-line parameter validation, service selection by enumerating Svchost netsvcs entries and choosing an unregistered service name, decryption of embedded payloads, decompression, writing files to disk, moving a service DLL into the Windows system32 directory, and storing configuration in the registry. One Lazarus infection chain report states Comebacker used HC256 and RC4 for string and configuration decryption, wrote timestamp data to C:\Windows\system32\AppxProvision.xml, dropped a decoy file named kjepl.xml, and stored configuration under HKLM\SYSTEM\ControlSet001\Services\kbddes\GUID. That same report says Comebacker deployed a service-stage wrapper, Compcat_v1.dll, which memory-loaded a new BLINDINGCAN variant. Separate reporting also describes a ChaCha20-encrypted Comebacker backdoor used in attacks on aerospace and defense organizations.
Targeting and campaign context in the content include Lazarus operations against aerospace and defense, software/IT, education, defense industrial base, U.S. healthcare, nonprofits, and an unnamed Middle East organization. Comebacker is specifically mentioned in Lazarus Medusa ransomware activity affecting or attempting to affect U.S. healthcare and Middle East targets, and in developer-focused supply-chain style campaigns using malicious package repositories. Microsoft also reported that Moonstone Sleet reused code from known Lazarus malware such as Comebacker.
High-confidence indicators and artifacts directly mentioned in the content include file paths C:\ProgramData\comms.bin and C:\ProgramData\Comms\ssh.bin; required execution parameters up45V3FR9ee9 and 760H33ls9L5S; the file C:\Windows\system32\AppxProvision.xml; decoy file kjepl.xml; registry path HKLM\SYSTEM\ControlSet001\Services\kbddes\GUID; and associated C2 infrastructure hxxp://166[.]88[.]11[.]10/upload/check.asp, hxxps://tronracing[.]com/upload/check.asp, and hxxp://23[.]27[.]140[.]49/Onenote/index.asp.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We observed a new version of the Comebacker malware leading to a new variant of their BLINDINGCAN remote access tool.
Malware and Tools · Comebacker : Customized backdoor and loader associated with Lazarus
"The arsenal includes Comebacker, a custom backdoor and loader exclusively associated with the group"
"Tools Used In Recent Campaigns... Comebacker backdoor"
4 distinct techniques documented for this family, organized by ATT&CK tactic.
"Comebacker... embedding it within seemingly innocuous Python and npm packages..." and "Alternate attack sequences have entailed the use of malicious npm packages... masquerading as... a technical skills assessment."
"Moonstone Sleet is observed to set up fake companies and job opportunities to engage with potential targets"; "delivering a trojanized version of PuTTY ... via apps like LinkedIn and Telegram as well as developer freelancing platforms"; "sending candidates a 'skills test' that instead delivers malware"
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus와 연계된 맞춤형 백도어 및 로더로, 침투 후 추가 페이로드 전달과 지속성 확보에 사용된다.
Customized backdoor and loader associated with Lazarus, used to support penetration and follow-on malicious activity in Medusa-linked campaigns.
Tool used by Lazarus in current campaigns (exact functionality not detailed in the content).
Custom backdoor/trojan used for lasting access as part of Lazarus intrusions that culminate in ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.