NukeSped is a Lazarus-associated backdoor and remote access trojan family used in multiple espionage and financially motivated intrusion sets. It has been observed across Windows, macOS, and Android, with reporting also referencing Linux-targeting activity in Lazarus campaigns where NukeSped-related tooling or closely aligned implants were deployed. Security vendors commonly treat NukeSped as a signature Lazarus malware family, and it has appeared in operations targeting South Korean public institutions, universities, logistics, IT, manufacturing, defense-related organizations, and cryptocurrency-focused victims.
NukeSped provides remote control of infected systems through command-and-control tasking. Documented capabilities include shell command execution, file management, system information collection, keylogging, screen capture, port forwarding, SOCKS-style proxying or tunneling, process termination, and in some variants process injection. Some samples support self-deletion and persistence through service-based or launcher-assisted mechanisms. Windows variants have been observed as staged payloads that drop packed loaders and service components, while macOS variants have appeared both as standalone trojans and as components in trojanized application chains. Android detections under the NukeSped naming convention have also been reported by vendors.
The malware family uses multiple communication patterns depending on variant. Reported implementations include raw TCP backdoors with custom authentication exchanges and RC4- or DES-protected traffic, HTTP POST-based initial communications, and HTTP-like fake protocol strings intended to resemble SSL or web traffic. Lazarus-linked NukeSped development has also shown recurring anti-analysis and evasion traits, including encrypted strings, custom packers, garbage API insertion, dynamic API resolution, anti-sandbox checks, and self-deleting batch-script logic.
Observed delivery and installation chains include spearphishing documents with malicious macros, watering-hole compromises exploiting vulnerable software, supply-chain style delivery through trojanized software or packages, and staged downloaders that retrieve NukeSped as a later payload. In more recent Lazarus activity, NukeSped has also appeared as a follow-on Windows payload in broader cross-platform credential-theft and remote-control campaigns. The family is closely associated with Lazarus and, in some reporting, with Andariel or Bluenoroff activity where operational overlap or subgroup ambiguity exists.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability... | ASEC has revealed attack cases where the Lazarus group used the vulnerability to spread NukeSped in 2022.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In a Lazarus attack campaign captured by ThreatBook in the second half of 2025, the Nukesped trojan drop path was /Library/Caches/System Settings — consistent with the trojan drop directory in this supply chain poisoning incident.
`dropper.vb_s` (named as we obtained it), 497-line VBScript implant classified as Trojan.NukeSped, a known Lazarus Group malware family.
Over the last 15 years, the group has developed RATs, including the following... ▪ NukeSped
39 distinct techniques documented for this family, organized by ATT&CK tactic.
NukeSped에서는 지속성 유지를 위한 기능이 존재하지 않기 때문에 직접 커맨드 라인 명령을 이용해 작업 스케줄러에 등록시키는 명령들도 확인된다.
This executable must be run with argument 15975345682 to execute
9999 CMD 명령어 실행 및 결과 데이터 전송 ... 전달받은 명령을 cmd.exe를 이용해 수행하고 결과를 C&C 서버에 전송한다.
NukeSped에서는 지속성 유지를 위한 기능이 존재하지 않기 때문에 직접 커맨드 라인 명령을 이용해 작업 스케줄러에 등록시키는 명령들도 확인된다.
공격 과정에서는 일반적인 MS-SQL 서버 대상 공격 사례와 유사하게 권한 상승을 목적으로 PrintSpoofer 악성코드가 함께 사용되었다.
사용되는 API와 DLL 이름 등의 문자열을 암호화하여 저장하고 있다... C&C 서버의 주소는 DES ECB 알고리즘을 이용해 인코딩되어 있다.
Dynamic resolution of Windows APIs ... The technique is very typical and has already been described [2, p.59].
This is achieved by sending the bot’s client-server traffic as a part of a fake TLS packet that mimics the TLS protocol and seemingly initiates a legitimate connection.
cmd.exe /c "ipconfig /all" ... cmd.exe /c "netstat -naop tcp"
감염된 시스템의 사용자 이름, 컴퓨터 이름, MAC 및 IP 정보 등 기본적인 정보를 Base64 인코딩하여 ... C&C 서버에 전송한다.
After the trojan runs with the C2_url, it first collects basic host information including hostname, username, OS type and version, CPU information, system time, and the user process list.
Malware has ability to gather information such as Windows product name, CPU name, username, etc.
ProtocolTcpPure 클래스를 보면 알 수 있듯이 Raw TCP 프로토콜을 이용해 C&C 서버와 통신한다.
NukeSped는 HTTP 통신을 위장하였다. 즉 아래와 같은 POST 요청을 전송한 후 정확히 매칭되는 HTTP 응답이 올 때에만 C&C 서버와 통신을 진행한다.
ModuleSocksTunnel 클래스에서는 이름과 같이 터널링 기능을 제공할 것으로 추정된다... C&C 서버와 해당 주소 간의 프록시로서 동작한다.
ModulePortForwarder 클래스에서는 이름과 같이 포트 포워딩 기능을 지원한다... 외부에 존재하는 공격자는 포트 포워딩 기능을 지원하는 NukeSped를 통해 감염 시스템 내부 즉 사설 네트워크에 존재하는 공격 대상과 통신했을 것으로 추정된다.
744 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus-linked VBScript implant/backdoor fetched by the PowerShell loader on Windows; it collects system data, browser extensions, and signs of Telegram use, then retrieves additional payloads while attempting to weaken local defenses.
NukeSped is referenced in connection with a DPRK BlueNoroff ClickFix kit, implying it is malware associated with that campaign/tooling.
A VBScript-based C2 implant used in the fake meeting lure infection chain on Windows. It supports command-and-control activity, checks for Telegram Web artifacts, inventories browser extensions including wallet-related ones, and may enable in-memory execution or additional payload delivery.
A Lazarus/BlueNoroff-linked VBScript C2 implant used in the campaign’s Windows chain. It performs host reconnaissance, process and browser-extension enumeration, optional Telegram Web usage checks, beacons to C2, and supports fileless execution or disk-dropped follow-on payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.