miniBlindingCan is a Lazarus Group remote access trojan and a simplified variant of the BlindingCan backdoor. ESET reported it in a cyberespionage intrusion against an aerospace company in Spain and noted it was delivered alongside LightlessCan via the HTTP(S) in-memory downloader NickelLoader. The activity was attributed with high confidence to Lazarus and aligned with Operation DreamJob tradecraft, using LinkedIn spearphishing with a fake Meta recruiter persona and malicious coding-challenge ISO files (Quiz1.iso and Quiz2.iso) as the initial infection vector. The campaign targeted aerospace-related know-how.
In the observed chain, victims executed decoy binaries from ISO images, after which DLL side-loading was used to deploy additional stages. NickelLoader was delivered via PresentationHost.exe side-loading a malicious mscoree.dll from C:\ProgramShared. miniBlindingCan itself was delivered via colorcpl.exe side-loading a VMProtect-obfuscated colorui.dll from C:\ProgramData\Adobe. The miniBlindingCan dropper used anti-debugging via a PEB BeingDebugged check, anti-sandbox behavior, and a parent-process check for colorcpl.exe.
The malware is also noted as previously reported by Mandiant under the name AIRDRY.V2. Related campaign infrastructure relied on compromised legitimate websites for command-and-control rather than attacker-owned servers. Reported compromised C2 sites in the broader campaign included bug.restoroad[.]com, hurricanepub[.]com, turnscor[.]com, mantis.quick.net[.]pl, www.radiographers[.]org, kapata-arkeologi.kemdikbud.go[.]id, barsaji.com[.]mx, www.keewoom.co[.]kr, kerstpakketten.horesca-meppel[.]nl, kittimasszazs[.]hu, and nrfm[.]lk.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One of these RATs is already known to be part of the Lazarus toolkit... To distinguish it, we put the prefix mini- in front of the variant’s name.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
“Both LightlessCan and miniBlindingCan resolve Windows APIs dynamically.”
“LightlessCan and miniBlindingCan use various types of process injection.”
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Variant/minimized form of BlindingCan referenced as part of the Operation DreamJob toolset; specific capabilities are not detailed in the provided content.
A reduced-functionality BlindingCan variant used by Lazarus, delivered by NickelLoader and deployed via DLL side-loading/reflective loading; supports a limited command set including system profiling, configuration update, download/decrypt file, and shellcode execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.