SCSKAppLink.dll is a Windows malware component attributed to the Lazarus Group and observed in campaigns targeting South Korean organizations, including defense and chemical-sector entities. It has been associated with watering-hole operations that compromise legitimate Korean websites and exploit vulnerabilities in INITECH INISAFE CrossWeb EX to infect visitors running unpatched software. In observed intrusions, the malware was injected into the legitimate signed INISAFE process INISAFECrossWebEXSvc.exe rather than replacing or modifying that executable directly.
Its primary documented role is as a downloader-stage implant. When running inside the targeted host process, it attempts to retrieve and execute additional malware from attacker-controlled infrastructure. Code analysis indicates process-aware branching logic, with explicit checks for multiple host processes; however, only the branch tied to the INISAFE process has been clearly documented as operational, and some other branches appeared incomplete. The malware therefore shows both process-injection behavior and post-compromise payload delivery functionality.
SCSKAppLink.dll has been linked to broader Lazarus intrusion activity involving compromised IIS servers used as malware distribution points, exploitation of client-side security software vulnerabilities for initial access, and follow-on deployment of additional Lazarus tooling such as loaders, downloaders, backdoors, keyloggers, and port-scanning components. Reporting also places it within campaigns that expanded from initial website compromise into wider enterprise intrusion activity against major Korean organizations. The malware is best characterized as a Lazarus downloader used on Windows systems as part of targeted exploitation chains leveraging vulnerable third-party security software.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MagicLine4NX 1.0.0.17 이하의 버전에서는 CVE-2021-26606 취약점이 존재한다. 해당 취약점은 버퍼 오버플로우 취약점으로 원격에서 임의의 명령어를 전송하여 악성코드 감염 등의 피해를 유발할 수 있다. | INISAFECrossWebEXSvc.exe의 취약점에 의해 악성코드 배포 사이트에서 라자루스 악성코드(SCSKAppLink.dll)가 다운로드된 후 실행된다.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After these attacks, the threat actor attempted to install an additional malware “SCSKAppLink.dll” in the infected system through INISAFE vulnerability attacks.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The group is known to use the watering hole technique for initial access. The group first hacks Korean websites and modifies the content provided from the site.
It was identified in the attack case at the time that the threat actor used poorly managed or vulnerable web servers as the initial access point. Ordinarily, when attackers find a web server with a vulnerable version from scanning, they use the vulnerability suitable for the version to install a WebShell or execute malicious commands.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader malware associated with Lazarus that is delivered via exploitation of vulnerable INISAFE CrossWeb EX installations. The content says it downloads and executes additional malware from an external source and can install attacker-designated malware to gain control of the system.
A Lazarus malware DLL downloaded and executed via exploitation of a vulnerable INISAFECrossWebEXSvc.exe process during the initial watering-hole compromise.
Lazarus-attributed malware DLL that is injected into the legitimate inisafecrosswebexsvc.exe process, contacts a remote URL, downloads an additional payload, and copies it as SCSKAppLink.dll under C:\Users\Public.
A Lazarus-linked DLL malware that is injected into the legitimate inisafecrosswebexsvc.exe process, contacts a remote URL, downloads an additional payload, and copies it as SCSKAppLink.dll for execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.