LazarAgent is a Windows malware family associated with the Lazarus Group and observed in targeted intrusions against South Korean organizations, including defense, chemical, IT, media, public-sector, and finance-related entities. It has been used in campaigns that combined watering-hole compromises of legitimate websites with exploitation of vulnerable local security software, including INITECH INISAFE CrossWeb EX and DreamSecurity MagicLine. In documented activity, LazarAgent was delivered through compromised websites that selectively served malicious content to intended victims, then executed within or alongside legitimate signed processes through DLL injection or DLL side-loading. One observed component, a malicious DLL injected into an INITECH process, downloaded and executed additional payloads, indicating a staged infection chain. Related Lazarus operations also used fileless components, internal reconnaissance, credential theft from Outlook and browsers, and follow-on tooling for lateral movement and persistence. Tradecraft linked to the same intrusion sets included use of WMI, occasional RDP or SSH access, and in some cases deployment of rootkit tooling via BYOVD to disable security products. LazarAgent is best understood as part of a broader Lazarus post-compromise and malware-delivery ecosystem used for espionage-oriented access, follow-on payload deployment, and network expansion inside selected victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MagicLine4NX 1.0.0.17 이하의 버전에서는 CVE-2021-26606 취약점이 존재한다. 해당 취약점은 버퍼 오버플로우 취약점으로 원격에서 임의의 명령어를 전송하여 악성코드 감염 등의 피해를 유발할 수 있다. | [파일 진단] Downloader/Win.LazarAgent (2022.05.04.02)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-associated downloader malware identified in the campaign. The content describes Lazarus using malware delivered via watering-hole attacks and vulnerable software to gain footholds and move laterally.
Named Lazarus-associated malware family appearing in the IOC/detection list provided by AhnLab.
Named as a related Lazarus malware strain in the IOC list; identified by AhnLab as part of related malware discovered during tracking.
A Lazarus-attributed malware component identified among samples tied to the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.