InfoHook is an information-stealing malware/infostealer associated with the North Korea-linked Lazarus Group. Reporting cited in the content places it in Lazarus intrusions involving Medusa ransomware and financially motivated extortion activity, including an attack against an unnamed entity in the Middle East and an attempted attack against a U.S. healthcare organization, with broader victimology in the period including U.S. healthcare and nonprofit organizations. The malware is described as being used alongside other Lazarus tooling such as Comebacker, BLINDINGCAN, ChromeStealer, Mimikatz, RP_Proxy, and Curl. High-confidence descriptions in the content characterize InfoHook as an information stealer that scans for and stages sensitive data for exfiltration. The content does not provide standalone infection-vector details or specific IoCs uniquely tied to InfoHook.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Lazarus Group's Medusa ransomware campaign includes the use of various tools - RP_Proxy, a custom proxy utility Mimikatz, a publicly available credential dumping program Comebacker, a custom backdoor exclusively used by the threat actor InfoHook, an information stealer previously identified as used in conjunction with Comebacker BLINDINGCAN (aka AIRDRY or ZetaNile), a remote access trojan ChromeStealer, a tool for extracting stored passwords from the Chrome browser.
"Tools Used In Recent Campaigns... Infohook data stealer"
3 distinct techniques documented for this family, organized by ATT&CK tactic.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
정보 탈취를 목적으로 사용되는 악성코드다.
Information-stealing malware used in Lazarus operations associated with financially motivated intrusions.
Tool used to discover and stage sensitive data for exfiltration prior to ransomware deployment (supporting double-extortion style operations).
Information-stealing malware used to collect data during intrusions supporting extortion operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.