TorisMa is a Lazarus Group malware family associated with Operation Dream Job, a highly targeted campaign that used recruiter-themed social engineering to compromise organizations in research, defense, and financial or payments sectors. It is a Windows implant delivered selectively as a second-stage payload only after an earlier-stage infection profiled the victim and backend infrastructure determined the host was of interest, including allow-list based gating by victim network characteristics. This selective deployment model indicates a tailored post-compromise tool used for higher-value targets rather than broad indiscriminate distribution.
The malware supports host reconnaissance and data theft. Reported capabilities include collecting local network configuration details such as IP and MAC address information, obtaining the current system time, and transmitting victim data to actor-controlled command-and-control infrastructure. Its command-and-control traffic is obfuscated through Base64 encoding and additionally protected with XOR and VEST-32 encryption. Samples have also been observed packed with Iz4 compression, consistent with Lazarus tradecraft aimed at hindering analysis and detection. TorisMa uses Windows API functionality during execution.
In the broader Lazarus intrusion chain, TorisMa appears as part of a custom malware ecosystem that includes tools such as Sumarta, DBLL Dropper, and DRATzarus. Delivery in documented Dream Job activity began with spearphishing emails carrying malicious Microsoft Word documents and macros that installed a first-stage reconnaissance implant; only selected victims subsequently received TorisMa. This places TorisMa in a post-exploitation role focused on intelligence collection and exfiltration within carefully curated victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Related Malware: AppleJeus BADCALL Bankshot BLINDINGCAN Cryptoistic Dtrack KEYMARBLE KiloAlfa SierraAlfa ThreatNeedle Torisma WannaCry
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
"Babuk can enumerate disk volumes, get disk information"; "Ryuk has called GetLogicalDrives ... and GetDriveTypeW"; "Cuba can enumerate local drives, disk type, and disk free space"; "Chimera ... fsutil fsinfo drives"
Multiple malware and threat groups are described as collecting/deriving local system time, date, timestamp, tick count, or time zone (e.g., "used time /t and net time \ip/hostname for system time discovery"; "collects the timestamp from the victim’s machine"; "can collect the time zone information from the system").
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-associated malware family listed as related malware.
Collects local MAC address via GetAdaptersInfo and the system IP address.
A second-stage Lazarus payload selectively delivered to whitelisted victims after an initial reconnaissance implant. It functions as the final backdoor/payload released only to targets deemed of interest.
Malware that Base64-encodes command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.