Brambul is a Windows SMB worm associated with North Korean state-linked activity tracked by the U.S. government as HIDDEN COBRA and widely linked to the Lazarus Group. It has been observed since at least 2009 and has been used alongside the Joanap backdoor, which is often deployed as a second-stage payload after Brambul gains access to additional systems. Reporting has tied its use to intrusions affecting organizations globally, including targets in South Korea and sectors such as media, aerospace, financial services, manufacturing, and critical infrastructure.
Brambul propagates by scanning local subnets and, in some variants, random external addresses for systems exposing SMB services. It attempts unauthorized access through brute-force authentication using embedded credential lists and common administrator account names. After successful compromise, it can copy itself to remote hosts, create and remove temporary shared resources, install itself or a payload as a service, and execute remotely, enabling lateral movement across Windows environments. Observed variants also check for remote desktop availability and can coordinate with Joanap components.
The malware collects victim host information and transmits compromise details to operator-controlled email accounts, supporting follow-on exploitation. Public technical reporting describes variants delivered as service DLLs, portable executables, or dropped by companion malware. Brambul’s primary role is worm-like propagation and credential guessing over SMB rather than long-term interactive control, but it materially supports broader post-compromise operations by establishing footholds and facilitating deployment of additional malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Alert (TA18-149A): HIDDEN COBRA – Joanap Backdoor Trojan and Brambul Server Message Block Worm
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The Justice Department today announced an extensive effort to map and further disrupt, through victim notifications, the Joanap botnet – a global network of numerous infected computers under the control of North Korean hackers... Computers infected with Joanap — known as “peers” or “bots” — became part of a network of compromised computers known as a botnet.
The email containing the system's IP address, hostname, username, and password
After copying the malware to the new system it then runs the file on the victim system using a malicious service.
If the malware is able to connect to these IP addresses, it will attempt to gain unauthorized access via the SMB protocol on port 445 using a brute-force password attack.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows 32-bit SMB worm that spreads laterally in victim networks over SMB, performs brute-force password attacks, and reports victim details to operators via email for follow-on remote operations.
A first-stage worm used to propagate Joanap and gain unauthorized access to computers by crawling from system to system and probing for access via certain vulnerabilities.
SMB worm that spreads across local subnets and random external IPs by brute-forcing SMB credentials on port 445, creates and deletes an adnim$ share, copies itself as mssscardprv.ax, installs via malicious service, and exfiltrates infection details by email. It can communicate with Joanap using RC4-protected communications.
A malicious Windows 32-bit SMB worm that spreads via SMB shares by using embedded credentials to brute-force access over ports 139 and 445. It harvests system information, propagates laterally, and sends victim host details and credentials to operators via email.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.