Bof is a Rust-based loader used by the North Korea-linked Lazarus Group sub-cluster BlueNoroff in the GhostHire campaign, part of the broader SnatchCrypto operation. Kaspersky reported that in GhostHire, BlueNoroff targeted Web3 developers and the blockchain sector via Telegram job lures and a ZIP-based coding assessment containing a malicious dependency. In Windows infections, DownTroy deployed multiple payloads including RooTroy, RealTimeTroy, a Go version of CosmicDoor, and Bof. Bof’s role is to decode and launch an encrypted shellcode payload stored in the C:\Windows\system32\ folder. High-confidence context ties its use to BlueNoroff/Lazarus activity against Web3-focused victims, particularly developers, as part of a multi-stage Windows intrusion chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Rust-based loader named Bof that's used to decode and launch an encrypted shellcode payload stored in the "C:\Windows\system32\" folder.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based loader used on Windows in the GhostHire campaign to facilitate execution/loading of additional payloads.
Rust-based loader used on Windows to decode and execute an encrypted shellcode payload stored under C:\Windows\system32\.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.