Lazardoor is a Windows backdoor associated with the Lazarus Group and observed in targeted intrusions against South Korean organizations, including defense, IT, media, public-sector, and finance-related entities. It has appeared in campaigns that used watering-hole attacks and exploitation of vulnerable South Korean security software products, including INISAFE CrossWeb EX, MagicLine4NX, VestCert, and TCO!Stream, to gain initial access and deliver follow-on payloads.
Operationally, Lazardoor has been used as an early-stage backdoor within broader Lazarus intrusion chains. Reported tradecraft includes deployment through compromised websites that selectively served malicious content to intended victims, use of DLL side-loading with legitimate Windows executables, and execution of additional payloads in memory to reduce visibility. In multiple cases, Lazarus paired legitimate executables with malicious DLLs placed in the same directory so that the malicious component would be loaded under the guise of a trusted process. Related activity also included fileless execution, staged loaders, and process injection.
Campaigns involving Lazardoor were linked to post-compromise activity such as command execution, internal reconnaissance, communication with attacker-controlled infrastructure, and delivery of additional malware families used for credential theft and browser or email data collection. In the same intrusion sets, Lazarus was observed using WMI for remote execution, RDP and SSH for internal access, and malware components that supported lateral movement and persistence. Some related operations also deployed rootkit capabilities and BYOVD techniques to disable security products, indicating that Lazardoor can function as one component in a larger, modular intrusion framework rather than as a standalone implant.
The malware has been detected under both Trojan and Backdoor classifications, but the observed behavior and campaign role support its characterization as a backdoor used for covert access and follow-on payload delivery in espionage-oriented Lazarus operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MagicLine4NX 1.0.0.17 이하의 버전에서는 CVE-2021-26606 취약점이 존재한다. 해당 취약점은 버퍼 오버플로우 취약점으로 원격에서 임의의 명령어를 전송하여 악성코드 감염 등의 피해를 유발할 수 있다. | [파일 진단] Backdoor/Win.Lazardoor (2022.07.06.00) ... Trojan/Win.Lazardoor (2022.05.04.02)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DevSync.cpl ... Trojan/Win.Lazardoor ... Adobe.dat ... Trojan/Win.Lazardoor ... rasgreeng.dll ... Trojan/Win.Lazardoor
9 distinct techniques documented for this family, organized by ATT&CK tactic.
145 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-associated malware identified in the campaign as a backdoor/downloader. It is downloaded and executed via PowerShell after exploitation of the VestCert vulnerability, and is also referenced in file detections as Trojan/Win.Lazardoor.
Backdoor malware used to maintain control on compromised systems. The content states the attackers create and register backdoor files as services and open TCP port 60012 for communications.
Backdoor used by the Lazarus group for initial compromise, delivered via a legitimate application and executed via DLL side-loading.
Named Lazarus-associated backdoor/trojan referenced in the IOC detection list.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.