TSMSISrv.dll is a 64-bit Windows DLL sideloading loader assessed in the provided reporting as bespoke Lazarus Group tooling used in an intrusion that later culminated in deployment of Medusa ransomware. It masquerades as the legitimate Terminal Services MSI Server DLL and is loaded by svchost.exe through the SessionEnv service, which starts automatically at boot as SYSTEM, providing persistent privileged execution. The sample was reportedly compiled on 2025-03-20 18:42:02 UTC with MSVC Visual Studio 2022 v17.3+, and detections cited in the content include Kaspersky Trojan.Win64.Lazarus.ey and ReversingLabs Win64.Trojan.Lazarus. The SHA-256 reported for the sample is aeebcd8c8b15645d7e71b68ac05e21e9a4c94f832c64044725d870b87b9573c7.
The loader is described as being built on the Windows 8 IME SDK SampleIME codebase as camouflage, reusing version information and RTTI/class names such as SampleIME, CSampleIME, CBaseDictionaryEngine, CCompositionProcessorEngine, CKeyStateComposing, and CTipCandidateList. Its persistence mechanisms include DLL sideloading via SessionEnv and COM hijacking through CLSID%s\InProcServer32 registry paths with ThreadingModel set to Apartment. Anti-analysis behavior includes two TLS callbacks that execute before DllMain. The sample also contains a standalone custom AES implementation, including AES S-box tables at file offset 0x72000-0x74000, assessed as being used for configuration protection and C2 communications.
The reporting links TSMSISrv.dll to a Hungarian incident in which the same researcher submitted both this loader and a Medusa ransomware sample, gaze.exe, within two weeks of each other. The seven-month gap between the loader compilation and the ransomware compilation is assessed in the content as evidence of a long-dwell intrusion chain in which Lazarus established persistent SYSTEM-level access before extortion. The report further assesses with high confidence that Lazarus operators acted as affiliates of the Medusa ransomware-as-a-service ecosystem in this case, with possible subgroup attribution to Andariel (APT45) or BlueNoroff, although that subgroup assessment is presented as likely rather than definitive.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The loader, built on the Windows 8 IME SDK with custom AES tables and dual TLS anti-analysis callbacks, was compiled seven months before the ransomware -- mapping a patient intrusion chain where Lazarus established persistent SYSTEM-level access first and deployed extortion payloads second.
Sample 2 ( TSMSISrv.dll ) is a DLL sideloading loader built on the Windows 8 IME SDK with custom AES S-box tables, dual TLS anti-analysis callbacks, and COM hijacking persistence via the SessionEnv service.
The loader, built on the Windows 8 IME SDK with custom AES tables and dual TLS anti-analysis callbacks, was compiled seven months before the ransomware -- mapping a patient intrusion chain where Lazarus established persistent SYSTEM-level access first and deployed extortion payloads second.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TSMSISrv.dll is a custom Lazarus DLL sideloading loader masquerading as a Terminal Services component. It gains persistent SYSTEM-level execution via the SessionEnv service, uses COM hijacking for persistence, executes anti-analysis TLS callbacks before DllMain, and uses a custom AES implementation for encrypted configuration/C2.
TSMSISrv.dll is a Lazarus-linked IME SDK-based DLL sideloading loader used for initial access and persistence. It abuses the SessionEnv service for privileged execution, uses COM hijacking for persistence, includes dual TLS anti-analysis callbacks, and custom AES routines to decrypt configuration and support beaconing/download of later-stage payloads including Medusa ransomware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.