Destover is a Windows malware family closely associated with the Lazarus Group, also tracked in some reporting under the broader DarkSeoul or Hidden Cobra activity clusters. It is best known for its role in the 2014 Sony Pictures intrusion, where it was used as part of a destructive operation that combined data theft, network propagation, backdoor functionality, and disk wiping. Public reporting also links Destover-related tooling and derivatives to earlier and later Lazarus operations, including South Korean destructive campaigns and subsequent reconnaissance-focused activity such as Operation GhostSecret.
Destover has been described both as a backdoor-capable implant and as part of a larger destructive malware suite. Reported capabilities include remote command execution, file transfer, system survey, process manipulation, proxying, arbitrary code execution, and inbound listening components. In Sony-related reporting, associated components propagated laterally through Windows SMB shares using brute-force authentication, copied themselves to remote hosts, and executed via administrative mechanisms. Destructive modules overwrote master boot records, damaged physical drives, deleted files, and rendered systems inoperable. Some variants or related Lazarus samples also used batch-file self-deletion mechanisms to remove binaries after execution.
The malware family is strongly tied to high-impact disruptive operations rather than commodity crime. It has been associated with attacks against entertainment, South Korean organizations across multiple sectors, and later global victim sets in finance, telecommunications, healthcare, higher education, and critical infrastructure through Destover-like derivatives. Later Hidden Cobra-linked implants showed code overlap, shared development artifacts, and similar fake-TLS command-and-control patterns with Destover, indicating continued evolution within the Lazarus malware ecosystem.
Destover is notable as one of the signature destructive malware families in the Lazarus arsenal, combining post-compromise control with wiper functionality to support sabotage, cover tracks, and amplify operational impact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
From Seoul to Sony The History of the Darkseoul Group and the Sony Intrusion Malware Destover Joanap Sierra(Alfa,Bravo, ...)
175.100.189.174 is embedded in 800f9ffd063dd2526a4a43b7370a8b04fbb9ffeff9c578aa644c44947d367266 and is also contacted by a606716355035d4a1ea0b15f3bee30aad41a2c32df28c2d468eafd18361d60d6, a documented Destover sample.
FROM SEOUL TO SONY: THE HISTORY OF THE DARKSEOUL GROUP AND THE SONY INTRUSION MALWARE DESTOVER
These clusters are mainly composed of the following malware families ... Destover
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Execute a binary on the system using cmd.exe and log the results into a temp file, which is then read and the logged results are sent to the control server. The command line: cmd.exe /c “<file_path> > %temp%\PM*.tmp 2>&1”
All important API calls have been base64 encoded and RC4 encrypted which will be decoded and decrypted at run time.
Both variants build their API imports dynamically using GetProcAddress
Once the theft is complete, they will try to destroy all evidence by deploying crimeware ransomware or wipers.
MITRE ATT&CK techniques: File deletion: malware can wipe files indicated by the attacker | Delete itself from disk using a batch file.
Our analysis shows a signed driver is being used to deploy a wiper that targets Windows devices... The developers are using a tried and tested technique of wiper malware, abusing a benign partition management driver... HermeticWiper uses a similar technique by abusing a different driver, empntdrv.sys.
MITRE ATT&CK techniques: Process discovery: implants can list processes running on the system
As part of its initialization, the implant gathers basic system information and sends it to its hardcoded control server 203.131.222.83 using SSL over port 443
List files in a directory. The directory path is specified by the control server.
These domains and IPv4 addresses are used to generate crafted TLS sessions similarly to the 'fake TLS' communication mechanisms ... includes a legitimate domain name in its SNI field yet is sent to a command and control IPv4 address.
The SMB worm... connects to a command and control (C2) infrastructure with servers located in Thailand, Poland, Italy, Bolivia, Singapore and the United States... It connects home every five minutes to send log data back to command and control (C2) infrastructure.
Over the following weeks, huge swathes of information stolen from Sony were released, including: personal information about employees and their families; email correspondence between employees at the company; information about company salaries, unreleased Sony films, and other information.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware tied in the report to the Sony Pictures intrusion and the broader DarkSeoul/Silent Chollima threat complex.
Mentioned as a wiper used by Lazarus Group that abused Eldos Rawdisk for direct filesystem access from userland.
Referenced Lazarus malware family used as a code-similarity/attribution point for the analyzed second-stage payload.
A known Lazarus malware family mentioned because the analyzed payload shares code similarities with it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.