LightlessCan is a Windows remote-access trojan used by the North Korea-linked Lazarus Group, particularly in Operation DreamJob espionage activity. Identified as a more sophisticated successor to BlindingCan, it was deployed against an aerospace organization in Spain through recruiter-impersonation spearphishing and coding-challenge lures delivered in disk-image files. The infection chain used DLL side-loading and a downloader to load LightlessCan.
LightlessCan supports extensive operator command handling for host and network reconnaissance, process and service management, registry operations, scheduled-task management, network configuration, file and directory operations, and execution of programs. It internally reimplements numerous functions commonly performed through Windows command-line utilities, reducing reliance on visible console execution and complicating endpoint monitoring and forensic analysis. The malware uses cryptographic protection and victim-specific execution guardrails that restrict payload decryption to intended systems. It has established persistence through scheduled tasks. Lazarus has used LightlessCan primarily to support espionage against aerospace and defense-related targets seeking sensitive technology and know-how.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The report compares ROOFDECK's reimplementation of common shell commands with a tactic also used by LightlessCan, which is associated with Lazarus.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining the victim's trust, the threat actor offers them a job and suggests an external communication channel where it can share a malicious PDF file that is described as a document with details about the offer. This file is typically a first-stage launcher that drops malware on the target's computer
“One of the LightlessCan commands allows creation of a new process via WMI.”
“This mapistub.dll dropper has persistence established via a scheduled task.”
“Both LightlessCan and miniBlindingCan resolve Windows APIs dynamically.”
“LightlessCan and miniBlindingCan use various types of process injection.”
“LightlessCan can create a new process in the security context of the user represented by the specified token…”
“Many of these Lazarus tools and configurations are encrypted on the file system, e.g., LightlessCan in grpedit.dat and its configuration in wlansvc.cpl.”
“LightlessCan bypasses command execution by implementing their functionality.”
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison to ROOFDECK's implementation of common shell-command functionality.
Mentioned solely as a comparison to ROOFDECK's implementation of common shell command functionality.
Mentioned only as a comparison to ROOFDECK's command implementation behavior; no operational details are provided in this reference.
Mentioned only as a comparison to another Lazarus-aligned toolset's command reimplementation behavior; the report does not describe its deployment in this campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.