CLOSESHAVE is a utility associated with APT38, a subgroup linked to the Lazarus Group / BlueNorOff. The provided content states that it is used to securely delete files from compromised systems, indicating an anti-forensics or operational cleanup role. It is listed among malware associated with BlueNorOff and specifically described as a utility that can securely delete a file from the system. High-confidence context ties it to North Korean-linked Lazarus ecosystem activity, particularly financially motivated operations attributed to APT38/BlueNorOff. No additional infection vector, platform specificity, or standalone indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
1 distinct technique documented for this family, organized by ATT&CK tactic.
The content includes secure deletion and overwrite behavior, e.g., 'APT29 has used SDelete to remove artifacts,' 'GreyEnergy can securely delete a file,' 'LiteDuke can securely delete files by first writing random data to the file,' and 'PowerDuke has a command to write random data across a file and delete it.'
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family associated with BlueNorOff operations.
Secure file deletion utility used to remove files in a way intended to prevent recovery (anti-forensics).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.