DurianBeacon is a Windows backdoor and remote access tool associated with North Korea-linked activity, particularly campaigns attributed or linked to the Andariel cluster within the Lazarus ecosystem. It has been observed in both Go and Rust implementations and has appeared in intrusions targeting South Korean organizations, including universities, ICT firms, electronics companies, shipbuilding, manufacturing, defense-related entities, automotive parts manufacturers, and semiconductor firms. DurianBeacon has also been listed among Andariel-developed implants in joint government reporting on DPRK cyber espionage.
DurianBeacon functions as a command-driven backdoor that establishes encrypted command-and-control communications and transmits basic host metadata after connecting, including user and system context details. Reported capabilities include arbitrary command execution, PowerShell execution, configurable sleep or hibernation behavior, interval changes, directory and drive enumeration, file upload and download, directory creation, file deletion, process termination, self-deletion, and SOCKS-style proxying. The Rust variant has additionally been described as using XOR packet encryption alongside SSL-style communications.
Operational reporting places DurianBeacon in broader intrusion chains involving AndarLoader, downloader components, abused enterprise software distribution mechanisms, and post-compromise credential theft tooling. In some campaigns it was installed through abuse of vulnerable enterprise software such as INNORIX Agent; in others, it was delivered after internal propagation through compromised software update workflows. DurianBeacon has also been observed alongside tooling such as Mimikatz, ProcDump, Meterpreter, MultiRDP, and browser credential theft utilities, indicating use in sustained post-compromise operations focused on persistence, internal control, credential access, and information theft.
The malware is best understood as part of a wider Andariel tradecraft evolution toward Go-based and mixed-language implants while maintaining longstanding targeting patterns centered on South Korean strategic sectors and defense-adjacent organizations. Its role in these operations is to provide durable remote access and flexible post-exploitation control over compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ DurianBeacon
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Over the last 15 years, the group has developed RATs, including the following... ▪ DurianBeacon
15 distinct techniques documented for this family, organized by ATT&CK tactic.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Beacon/backdoor family with variants implemented in Go and Rust, used in Andariel-associated campaigns.
Go로 개발된 백도어/RAT로 SSL을 사용해 C&C와 통신하며, 시스템 정보 전송 후 명령 실행, 파일 업로드/다운로드, 디렉터리 조작, 자가 삭제, Socks Proxy 등의 기능을 제공한다.
Previously observed Go-based malware/tool associated with Andariel, referenced as historical context for the group's malware usage.
A backdoor available in both Go and Rust implementations. It communicates over SSL, and the Rust version also supports XOR-encrypted packets. It collects host information, executes commands, manages files and directories, and exchanges structured command/response packets with the C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.