LightlessCan is a Lazarus Group backdoor/RAT publicly documented by ESET in 2023 after an intrusion against an aerospace company in Spain. It was delivered in Operation DreamJob-style social-engineering attacks using fake recruiter personas and job-themed lures, including ISO files and DLL side-loading chains. ESET described it as a successor to BlindingCan and a significant advancement in stealth and sophistication.
Its core distinguishing feature is that it implements many Windows command-line functions internally rather than invoking noisy console utilities, reducing forensic and EDR visibility. Reported built-in functionality overlaps with commands such as ipconfig, net, netsh, netstat, ping, reg, sc, tasklist, wmic process call create, nslookup, schtasks, systeminfo, arp, and mkdir. ESET reported support for up to 68 command IDs, with 43 implemented in version 1.0. The malware also uses execution guardrails that bind decryption to victim-specific environment characteristics, hindering analysis, and the broader intrusion chain used strong cryptography including AES-128 and RC6.
In the Spain aerospace intrusion, LightlessCan was delivered after an HTTP(S) in-memory downloader named NickelLoader. Delivery chains included fixmapi.exe side-loading mapistub.dll from C:\ProgramData\Oracle\Java\ and a more complex tabcal.exe/HID.dll chain that dropped additional stages including grpedit.dat as the LightlessCan payload and wlansvc.cpl as configuration. The complex chain stored victim system characteristics from BIOS-related registry paths in %WINDIR%\System32\4F59FB87DF2F to enable environment-bound decryption. Persistence via a scheduled task was also reported in the simpler chain.
The malware is associated with Lazarus tradecraft more broadly. Multiple reports cite TLS callbacks as a documented Lazarus evasion technique seen in LightlessCan and other Lazarus tool families. Additional reporting states that another Lazarus-linked downloader/backdoor, Tropidoor, directly implemented Windows commands in a manner similar to LightlessCan, and ASEC reported overlaps between Tropidoor and LightlessCan. LightlessCan has been referenced in connection with Lazarus targeting of defense and aerospace organizations, particularly through recruiter-themed phishing and job-offer campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The “car.dll” downloader is characterized by implementing Windows commands internally, similar to the LightlessCan malware of the Lazarus group disclosed in a past ESET report.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining the victim's trust, the threat actor offers them a job and suggests an external communication channel where it can share a malicious PDF file that is described as a document with details about the offer. This file is typically a first-stage launcher that drops malware on the target's computer
“One of the LightlessCan commands allows creation of a new process via WMI.”
“This mapistub.dll dropper has persistence established via a scheduled task.”
“Both LightlessCan and miniBlindingCan resolve Windows APIs dynamically.”
“LightlessCan and miniBlindingCan use various types of process injection.”
“LightlessCan can create a new process in the security context of the user represented by the specified token…”
“Many of these Lazarus tools and configurations are encrypted on the file system, e.g., LightlessCan in grpedit.dat and its configuration in wlansvc.cpl.”
“LightlessCan bypasses command execution by implementing their functionality.”
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Lazarus malware/tool family associated with TLS callback anti-analysis and similar evasion behavior.
LightlessCan is referenced as a Lazarus tool family sharing anti-analysis techniques, particularly TLS callback usage, with the analyzed loader.
Named Lazarus-associated tool referenced as sharing traits with ScoringMathTea; no additional functional details provided in the content.
Referenced as another Lazarus Group RAT; no additional functional details provided in the content beyond being a RAT used by Lazarus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.