YamaBot is a Lazarus Group remote access trojan associated in particular with the Andariel cluster and used in North Korean espionage operations. It has been observed in campaigns targeting sectors including energy, and has been linked to intrusions against organizations in countries such as the United States, Canada, Japan, and elsewhere. Reporting also describes YamaBot as part of the broader Andariel malware arsenal alongside families such as VSingle, MagicRAT, TigerRAT, and Jupiter/EarlyRAT.
YamaBot is implemented in Go and has been documented in both Linux- and Windows-targeting variants, with platform-specific command handling. It communicates with command-and-control infrastructure over HTTP and fingerprints infected hosts by collecting identifiers such as hostname, username, and, on Windows, MAC address. Device metadata and command results are protected with RC4 and Base64 encoding and exchanged through HTTP cookie fields, while server tasking is delivered through HTTP response headers. When transmitting larger data, the malware can disguise outbound content as multipart BMP-like data to blend exfiltration into web traffic.
Its supported functionality includes remote command execution, file and directory listing, process information collection, file download, configurable sleep or beacon intervals, and self-uninstallation. The Linux variant primarily executes shell commands through the system shell, while the Windows variant exposes multiple built-in commands for filesystem interaction and execution control. These capabilities make YamaBot suitable for persistent post-compromise access, reconnaissance, and selective data theft during hands-on-keyboard intrusions.
Operationally, YamaBot has been observed after exploitation of internet-facing enterprise infrastructure, including VMware Horizon systems compromised via Log4Shell, and in some cases was deployed after other Lazarus implants were detected in order to preserve access. Its use aligns with Andariel tradecraft that combines custom RATs with credential theft, lateral movement, tunneling, and data exfiltration in support of long-term espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The initial vector was the exploitation of the Log4j vulnerability on exposed VMware Horizon servers... Cisco Talos identified the exploitation of the Log4Shell vulnerability on VmWare Horizon public-facing servers as the initial attack vector.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Talos has discovered the use of two known families of malware in these intrusions — VSingle and YamaBot. ... A third intrusion set worth noting here is one where we saw the use of a third bespoke implant known as YamaBot.
Over the last 15 years, the group has developed RATs, including the following... ▪ YamaBot
Over the last 15 years, the group has developed RATs, including the following... ▪ YamaBot
13 distinct techniques documented for this family, organized by ATT&CK tactic.
"Target Windows OS: hostname, username, MAC address" and function name "utilities.GetMacAddress"
"if the size of the data to be sent exceeds a certain size ... it is sent disguised as multi-part BMP data instead of captcha_val" ... "Content-Type: multipart/form-data" ... "filename=\"recaptcha.png\""
YamaBot is a custom-made GoLang-based malware family. It uses HTTP to communicate with its C2 servers.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named Lazarus-associated malware family used in the referenced campaign; specific functionality not detailed in the provided content.
New malware family introduced in the described Andariel campaign (no further details provided in the content).
Custom Go-based Lazarus RAT using HTTP C2. Sends initial host profiling (computer name, username, MAC) and provides standard RAT functions: file/directory listing, process reporting, file download, arbitrary command execution, and self-uninstall. Deployed as an alternative implant when VSingle was detected/blocked.
A custom GoLang-based Lazarus RAT that communicates over HTTP with C2 servers, sends host information to C2, and supports file and directory listing, process reporting, file download, arbitrary command execution, and self-uninstall.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.