Hangman is a malware family associated with Lazarus Group activity and is linked to the cluster of operations commonly referred to as Operation Troy and DarkSeoul. It was observed in use during roughly 2014 to 2015 as part of the broader Lazarus malware ecosystem, alongside families such as Destover, Duuzer, and SpaSpe. Public reporting places Hangman within a long-running set of North Korea-linked intrusion operations that have targeted organizations in East Asia and beyond.
High-confidence public information in this context does not establish a more specific functional classification for Hangman than that it is a Lazarus-associated malware family. Likewise, the available facts here do not directly confirm its precise delivery mechanism, platform scope, or discrete capabilities independent of the broader actor’s tradecraft. It is best understood as one of several malware families used by Lazarus during the mid-2010s period in campaigns tied to destructive and espionage-oriented operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group has deployed multiple malware families across the years, including malware associated with Operation Troy and DarkSeoul, the Hangman malware (2014-2015) and Wild Positron/Duuzer (2015).
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named Lazarus-associated malware family referenced as part of the group's historical arsenal.
Lazarus-associated malware family mentioned as historical background.
Malware family listed as associated with the Lazarus cluster in the paper.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.