Scout is a malware name used for at least two distinct Windows espionage toolsets and should be disambiguated by operator context. In Lazarus operations, Scout is a first-stage downloader observed from around 2022 as a successor to the Volgmer backdoor in intrusions against Korean organizations and enterprises, including defense, manufacturing, ICT, and financial targets. It reuses aspects of Volgmer’s configuration-loading and command-and-control design but is more narrowly focused on retrieving and executing follow-on payloads, including in-memory execution and later payload injection capabilities. Lazarus-associated activity involving Scout has been linked to broader intrusion chains that used spearphishing, watering-hole compromises, and exploitation of vulnerabilities in Korean security software, with some operations also employing registry-based persistence and defense-evasion measures.
Separately, Scout is also the first-stage component in Hacking Team’s Remote Control System spyware architecture, paired with second-stage modules known as Soldier or Elite. In that ecosystem, Scout installs itself, checks for other running instances, applies antivirus-bypass techniques, gathers basic system information, and checks for upgrades of itself or the second-stage spyware. The second stage provides extensive surveillance functions including credential and browser-data theft, clipboard theft, screenshot capture, camera activation, geolocation via Wi-Fi networks, Skype call recording, keylogging, mouse-click monitoring, and staged data storage and exfiltration. Post-2015 samples of this Hacking Team architecture were observed in targeted espionage operations in multiple countries and were commonly delivered as executables disguised as documents in spearphishing-style lures.
Because the name Scout refers to materially different malware used by unrelated actors, analysts should qualify references as Lazarus Scout or Hacking Team RCS Scout where possible.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We also confirmed that since 2022, a downloader named Scout has been used in attacks instead of Volgmer. The basic operating mechanism of Scout is similar to the previous one, with the only difference in the actual features.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
For the last few years, the group launched watering hole attacks to attack multiple Korean enterprises and organizations in the fields of defense, satellite, software, and media.
Their method for initial access involved the exploitation of a security vulnerability of a Korean financial security certification software.
The Lazarus group usually employed spear phishing and supply chain attacks, usually disguising the malware as legitimate programs in their attack process.
The Lazarus group usually employed spear phishing and supply chain attacks, usually disguising the malware as legitimate programs in their attack process.
As for the distribution vector of the post-leak samples we analysed, in at least two cases, we detected the spyware in an executable file disguised as a PDF document. The names of the files suggest the malware was spread via spear-phising emails sent to high-profile targets such as diplomats
Volgmer, which usually runs by being registered as a service, is installed with a name that disguises it as a legitimate file.
0x5459 Self-delete. | Besides the timestomping technique, the Lazarus group uses a variety of anti-forensic techniques such as file deletion and data concealment in their attack process.
After creating the Volgmer DLL in the path %SystemDirectory%, the dropper sets the time configuration information to be the same as the Notepad (notepad.exe) file. This timestomping is one of the major anti-forensic techniques employed for the purpose of evading timeline analysis.
Collected data is packed, encrypted and stored in the registry and later sent to the C&C server
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus-linked downloader observed from around 2022 onward that replaced Volgmer in some operations. It retrieves encrypted configuration data from the registry or overlay data, communicates with C2 using HTTP/HTTPS, downloads additional payloads from external sources, and executes them in memory; later versions add configuration management, payload injection, and self-delete capabilities.
A Hacking Team backdoor referenced only as historical comparison to what the original bootkit deployed.
First-stage component of Hacking Team's RCS that installs itself, checks for other instances, performs AV-bypass tricks, collects basic system information, and checks for upgrades of itself and second-stage modules.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.