Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
we identified the suspicious file in question to be a version of the OpenCarrot Windows OS backdoor, previously identified by IBM XForce as part of Lazarus group activities.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
OpenCarrot implements executable code in a section named .vlizer indicating the use of code virtualization for obfuscation.
Filesystem and process manipulation: Process termination, DLL injection, and file deletion, renaming, and timestomping.
Reconnaissance: File and process attribute enumeration, scanning and ICMP-pinging hosts in IP ranges for open TCP ports and availability.
At time of discovery, the email server was beaconing outbound to infrastructure we now attribute to the ScarCruft threat actor.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool associated with a North Korean compromise of a Russian missile engineering company.
A feature-rich Windows backdoor used for persistent compromise. It supports reconnaissance, file and process manipulation, DLL injection, C2 reconfiguration, proxying communications through internal hosts, named-pipe and TCP-based command handling, and can facilitate broader network compromise.
A backdoor referenced as another Lazarus-associated malware family that supports behavior similar to Volgmer's activation and communication logic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.