SierraAlfa is a Lazarus Group malware family associated with North Korean state-sponsored intrusion activity. It has been observed using resilient command-and-control tradecraft by randomly selecting from multiple hard-coded command-and-control servers and retrying with alternate servers when transmission fails, indicating an emphasis on maintaining communications during disrupted operations. SierraAlfa has also been used for lateral movement within Windows enterprise environments by accessing administrative SMB shares such as ADMIN$, consistent with post-compromise propagation and remote operations across internal networks. The malware is part of the broader Lazarus toolset used in espionage, financially motivated, and disruptive campaigns targeting sectors including banking, defense, software, pharmaceuticals, cryptocurrency, manufacturing, and electric infrastructure. Based on the available facts, SierraAlfa is best characterized as a Lazarus backdoor used for command-and-control and internal movement on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-associated malware family listed as related malware.
Malware that randomly selects among hard-coded C2 servers and retries with another if transmission fails.
Lazarus malware with fallback C2 behavior and SMB-based lateral movement via the ADMIN$ share.
Selects a hard-coded C2 server at random and retries with a different hard-coded C2 if transmission fails.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.