CookieTime is a Lazarus-associated Windows malware cluster, also referred to as LCPDot, that has been used in espionage operations and later-stage intrusions against high-value targets including defense-sector organizations and, in related Lazarus activity, cryptocurrency and decentralized-finance entities. Activity associated with the cluster has been observed since at least 2020 and shows technical and operational overlap with other Lazarus tooling, including ThreatNeedle, Manuscrypt, DeathNote, and ScoutEngine-related tradecraft.
CookieTime has functioned both as an interactive backdoor and as a downloader for additional payloads. Reported capabilities include receiving and executing operator commands, collecting host and system information, enumerating drives, files, and processes, terminating processes, changing working directories, creating new processes, transferring files in both directions, deleting files, updating configuration, and performing anti-forensic actions such as timestomping and secure deletion. In later intrusions it was also used to retrieve and stage additional Lazarus malware families during post-compromise expansion and lateral movement.
The malware communicates over HTTP and has been observed embedding encoded data in cookies. Lazarus infrastructure associated with CookieTime has used multi-stage command-and-control designs and steganographic techniques, including command delivery concealed within image-like content, to reduce exposure of core control nodes and selectively service higher-value victims. Related campaigns also showed execution through service-based mechanisms and DLL side-loading, consistent with Lazarus efforts to blend into legitimate software behavior and evade detection.
CookieTime has appeared in broader Lazarus intrusion chains delivered through recruiter-themed social engineering, trojanized software, and fake job-opportunity lures. In Operation DreamJob and related DeathNote activity, it was found on compromised hosts after initial infection and used to download further tooling. The cluster is widely assessed as part of Lazarus’s modular malware ecosystem rather than a standalone commodity family, and it remains notable for its role in selective victim management, payload delivery, and sustained post-exploitation within strategically important environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We believe with high confidence that the Lazarus group is linked to this malware as we identified similar malware in the CookieTime cluster. The CookieTime cluster, called LCPDot by JPCERT, was a malware cluster that was heavily used by the Lazarus group until recently.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... T1071.001 Application Layer Protocol: Web Protocols Use HTTP as C2 channel with backdoor
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/cluster listed as part of Lazarus expansion and aligned with Jade Sleet.
Referenced Lazarus-linked malware noted for a distinctive registry-path/configuration retrieval method reused/echoed by ScoutEngine.
A Lazarus backdoor/downloader that historically executed commands from C2 directly and more recently downloads additional payloads. It was used for lateral movement and to deploy further malware.
A Lazarus-linked backdoor cluster used in trojanized applications, with C2 communications over HTTP using RC4 and base64, and capabilities to gather system information, enumerate files/processes, execute commands, manipulate files, and exfiltrate data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.