LazarLoader is a Windows malware family associated with the Lazarus Group and used as part of multi-stage intrusion chains against organizations in South Korea. It has been observed in campaigns targeting sectors including defense, chemical, IT, media, public institutions, and finance, often alongside other Lazarus tooling such as Lazardoor, LazarAgent, and credential-stealing components. The malware has been linked to exploitation of vulnerable South Korean security software and to execution through trusted Windows processes and DLL side-loading chains.
LazarLoader functions primarily as a staged loader or downloader that retrieves and launches additional payloads. Reported variants and related components have been used to download follow-on malware, decrypt embedded payloads in memory, and execute them within legitimate processes. In some observed chains, LazarLoader-related DLLs were injected into legitimate software components or side-loaded through signed or benign executables, including abuse of Windows binaries to blend malicious execution with normal system activity. A related side-loading implementation used a malicious DLL containing an AES-128-encrypted embedded binary that was decrypted at runtime and executed in memory.
Delivery has been tied to watering-hole operations exploiting vulnerabilities in software widely deployed in South Korean environments, including INISAFE CrossWeb EX, MagicLine4NX, VestCert, and TCO!Stream. In these campaigns, compromised websites selectively served exploit content to intended victims, after which Lazarus malware was downloaded and executed. LazarLoader has also appeared in intrusion sets that relied on DLL side-loading after initial compromise, enabling stealthy execution and staging of additional malware.
Observed tradecraft around LazarLoader and closely related Lazarus tooling includes process injection, in-memory execution, defense evasion through use of legitimate host processes, and internal reconnaissance or follow-on deployment of credential theft and backdoor capabilities by companion malware. Technical overlaps noted by defenders include custom decryption logic and NTDLL unhooking behavior seen in later malware assessed as sharing characteristics with LazarLoader. Overall, LazarLoader is best understood as a Lazarus-associated Windows loader used to establish execution of subsequent payloads during targeted espionage-oriented intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MagicLine4NX 1.0.0.17 이하의 버전에서는 CVE-2021-26606 취약점이 존재한다. 해당 취약점은 버퍼 오버플로우 취약점으로 원격에서 임의의 명령어를 전송하여 악성코드 감염 등의 피해를 유발할 수 있다. | [파일 진단] Trojan/Win.LazarLoader (2022.06.22.03) ... Trojan/Win.LazarLoader (2022.09.07.00)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
cryptrsa.cpl ... Trojan/Win.LazarLoader ... scrapkisvc.dll ... Trojan/Win.LazarLoader ... softoknhelp.dll ... Trojan/Win.LazarLoader
9 distinct techniques documented for this family, organized by ATT&CK tactic.
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus Group-associated malware family referenced as technically similar to Dohdoor (overlapping tradecraft such as NTDLL unhooking in earlier variants).
Referenced as a Lazarus-associated loader with similar decryption (XOR-SUB) and EDR-evasion (NTDLL unhooking) tradecraft; mentioned for tooling overlap comparison with Dohdoor.
Referenced as a related loader family whose tradecraft overlaps with Dohdoor (custom XOR-SUB decryption and NTDLL unhooking for EDR evasion).
Downloader previously associated with Lazarus; referenced here due to tactical/technical similarities with Dohdoor (no direct use in this campaign is confirmed in the text).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.