Duuzer is a Lazarus-linked Windows backdoor trojan associated with cyber-espionage activity against South Korean organizations, particularly campaigns observed in 2015 that targeted sectors including manufacturing. It has been tracked alongside other Lazarus malware such as Brambul and Joanap and is part of the broader malware ecosystem tied to the North Korean threat cluster also known as Hidden Cobra. Duuzer is notable both as an operational implant and as a code lineage reference point, with later malware such as Rising Sun reported to reuse portions of its source code.
Public reporting links Duuzer to intrusions intended to compromise victim systems and enable remote control, post-compromise activity, and data theft. The malware is characterized as a backdoor trojan rather than a self-propagating worm or ransomware component. Its use fits Lazarus tradecraft seen across multiple campaigns, including code reuse, modular tooling, and deployment in targeted operations against strategic regional victims. Duuzer has been referenced in connection with the DarkSeoul and Operation Troy historical tracking of Lazarus activity, although the strongest direct reporting places it in 2015 South Korea-focused operations.
Duuzer targets Windows environments. High-confidence reporting supports its role in establishing unauthorized access and supporting follow-on espionage objectives, including exfiltration of victim data. It is associated with a state-linked threat actor known for blending espionage, sabotage, and financially motivated operations, but Duuzer itself is most directly tied to targeted backdoor access in espionage-oriented intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Duuzer back door Trojan targets South Korea to take over computers Brambul Duuzer Joanap Lazarus Group
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus Group backdoor (circa 2015) whose source code was reused in the Rising Sun implant framework.
Backdoor trojan targeting South Korea and linked to Lazarus; also referenced in WannaCry attribution reporting.
Backdoor used in espionage-focused attacks against South Korean organizations, particularly in manufacturing.
Malware family listed as associated with the Lazarus cluster in the paper.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.