Akdoor is a Windows backdoor associated with North Korean threat activity, including operations attributed to Lazarus, and has also been referenced in relation to Kimsuky-linked delivery chains through vendor detection naming. It has been observed in targeted intrusions against South Korean organizations, including defense-sector entities and other domestic companies, where operators used modified or injected DLL components rather than conventional standalone malware.
Akdoor has been identified in campaigns where attackers injected a malicious DLL into legitimate signed software to execute within a trusted process and retrieve additional payloads from attacker-controlled infrastructure. Related activity shows process-aware branching logic, staged downloading of follow-on malware, and use of in-memory execution. Separate Akdoor-attributed samples were embedded in tampered DLL libraries derived from legitimate components such as graphics, XML, plugin, and filesystem-related libraries. These variants altered or added exported functions, sometimes operated as Windows services, and depended on specific arguments, alternate data streams, or companion data files to decrypt and launch embedded PE payloads in memory before initiating command-and-control communications.
The malware’s tradecraft emphasizes defense evasion and modular post-compromise flexibility. Observed variants hid execution material in alternate data streams, used external encrypted data blobs and keys, and changed behavior based on runtime inputs. Some samples were packed to hinder analysis, while others were designed to appear benign during superficial inspection because much of the original legitimate library code remained intact. This architecture allowed operators to swap payload logic and command-and-control information without replacing the visible host component.
Akdoor has been linked to broader Lazarus intrusion clusters targeting South Korean industry, including defense and chemical-related organizations, and overlaps have been noted with tooling associated with the NukeSped or Manuscrypt ecosystem. A related malware family, AkdoorTea, has been described as sharing commonalities with Akdoor and appearing in recruiter-themed social-engineering campaigns targeting software developers. Across reporting, Akdoor is best characterized as a Windows backdoor used in targeted espionage-oriented operations, often as one stage within a larger multi-component intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AhnLab’s anti-malware software, V3, is currently detecting and blocking the files using the following aliases. – VBS file: Dropper/VBS.Akdoor
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon running the script file with the VBS extension... Ultimately, when the user runs the VBS, a malicious activity commences in parallel with the execution of the PDF file.
매직라인 취약점을 악용한 워터링 홀은 ... 언론사 기사 클릭할 때 악성코드에 감염되는 조건은 IP 필터링과 매직라인 취약점이 존재해야 합니다.
Ultimately, when the user runs the VBS, a malicious activity commences in parallel with the execution of the PDF file.
또한 기존 VC++ 파일을 Vmprotect로 패킹하여 전체 코드 패턴을 바꿨기 때문에 코드 변경 여부와 기능 파악을 어렵게 하였다.
The attacker also added ‘.pdf’ in front of the extension to trick users... resulting in the users mistaking the file for a PDF file even though it is a VBS file.
실행 과정에서 ADS (Alternate Data Streams) 데이터를 읽는다. ADS를 이용해 실행에 필요한 악성 데이터를 사용자 눈에 보이지 않게 숨겼다.
84 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as related to AkdoorTea; described as a variant of the NukeSped/Manuscrypt implant.
Named malware family listed in the detection names associated with the tracked Lazarus activity.
A Lazarus-associated trojan/backdoor family referenced in the IOC list of related malware strains.
A malicious VBS dropper that disguises itself as a PDF, launches an innocuous PDF to deceive the user, and writes a Base64-encoded DLL to C:\ProgramData for execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.