LazarShell is a Windows malware family associated with the Lazarus Group and observed in targeted intrusions against South Korean organizations, including defense and chemical-sector entities. It has been used in campaigns that combined watering-hole compromises of legitimate websites with exploitation of vulnerable local security software, notably INITECH INISAFE CrossWeb EX and, in related intrusion chains, DreamSecurity MagicLine4NX.
In documented activity, LazarShell was delivered by abusing a legitimate, signed INITECH process as an execution host. A malicious DLL identified as SCSKAppLink.dll was injected into the INISAFE CrossWeb EX service process and, when running in that context, contacted attacker-controlled infrastructure to download and execute additional malware. The code contained host-process-aware branching logic and was assessed as part of a broader Lazarus toolset that also included downloader, backdoor, loader, keylogging, port-scanning, and rootkit components.
The surrounding intrusion activity indicates LazarShell functioned as part of a multi-stage post-compromise framework. Lazarus operators used compromised websites to selectively target victims, then leveraged vulnerable software components for code execution and malware deployment. Subsequent operations in related cases included internal propagation via WMI and occasional use of RDP or SSH, establishment of persistence through service creation, and defense evasion through rootkit deployment and bring-your-own-vulnerable-driver techniques to disable security products. The malware family is therefore best understood as one element of a larger Lazarus intrusion ecosystem focused on stealthy access, payload delivery, and follow-on compromise inside enterprise Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MagicLine4NX 1.0.0.17 이하의 버전에서는 CVE-2021-26606 취약점이 존재한다. 해당 취약점은 버퍼 오버플로우 취약점으로 원격에서 임의의 명령어를 전송하여 악성코드 감염 등의 피해를 유발할 수 있다. | [파일 진단] Downloader/Win.LazarShell (2022.05.04.02)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The IOC of the related malware strains discovered so far is as follows: ... Downloader/Win.LazarShell ... Trojan/Win.LazarShell ...
1 distinct technique documented for this family, organized by ATT&CK tactic.
50 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-associated downloader/shell component observed in the campaign.
Named Lazarus-associated malware/tool referenced in detection names among related IOCs.
A named Lazarus-associated malware strain appearing in AhnLab's IOC list, classified in the content as both downloader and trojan detections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.