BottomLoader is a DLang-based downloader malware associated with the Lazarus Group’s Operation Blacksmith campaign and linked in reporting to the DPRK-aligned Andariel/Onyx Sleet cluster. Cisco Talos described it as a downloader used to retrieve additional payloads, including the custom proxy tool HazyLoad, on infected endpoints. Reported capabilities include downloading next-stage payloads via PowerShell Invoke-WebRequest, uploading files via PowerShell WebClient UploadFile, and establishing persistence by writing a .URL InternetShortcut file into the Windows Startup directory to trigger payload download. In the broader campaign context, Operation Blacksmith opportunistically targeted internet-exposed enterprise infrastructure through exploitation of n-day vulnerabilities, notably CVE-2021-44228 (Log4Shell), including publicly facing VMware Horizon servers. Talos reported victimology spanning manufacturing, agricultural, and physical security organizations, with observed overlap in tactics and tooling with activity attributed to North Korea’s Andariel/Onyx Sleet. Separately, a 2024 joint FBI-led advisory listed BottomLoader among Andariel-developed RATs and implants associated with espionage activity targeting defense, aerospace, nuclear, engineering, and to a lesser extent medical and energy sectors. The provided content does not include BottomLoader-specific hashes or other unique IOCs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ BottomLoader
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DLang-based downloader that uses PowerShell (Invoke-WebRequest / WebClient.UploadFile) to download/execute next-stage payloads and upload files; can establish persistence by creating a .URL shortcut in the Startup folder to re-run the download command.
Loader used to deploy additional tooling/implants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.