Wild Positron is a Windows malware family associated with the Lazarus Group and historically linked to the cluster of operations that also used Duuzer and other Lazarus implants during the mid-2010s. It is part of the broader Lazarus malware ecosystem and has been noted for code overlap with later Lazarus tooling, including shared HTTP wrapper functionality seen in CRAT and Rising Sun, indicating sustained internal code reuse across the actor’s development pipeline. Wild Positron is best understood as a Lazarus backdoor or remote-access implant used in targeted intrusions rather than as a commodity malware family.
The malware has been associated with Lazarus campaigns spanning espionage and disruptive activity, and its appearance alongside other Lazarus families places it within the group’s long-running operational toolkit. Reported overlap with implants tied to Operation Troy, DarkSeoul, Hangman, and related Lazarus activity suggests it was used during a period when the actor was deploying multiple interoperable malware families across strategic campaigns. The available information supports attribution to Lazarus, but does not provide high-confidence detail on Wild Positron’s specific infection vector, victimology, or full feature set beyond its role as an implant sharing core communications code with other Lazarus malware.
Wild Positron targets Windows environments. Based on its characterization as a Lazarus implant with shared communications components and its grouping with other Lazarus backdoors, it is assessed to support post-compromise access and operator control, but granular capabilities beyond that are not currently available from the supplied facts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group has deployed multiple malware families across the years, including malware associated with Operation Troy and DarkSeoul, the Hangman malware (2014-2015) and Wild Positron/Duuzer (2015).
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus-linked implant mentioned for code-reuse comparison with CRAT.
Lazarus-associated malware family mentioned as part of the actor's broader malware portfolio.
Lazarus-associated malware family mentioned as historical background.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.