Researchers tied the VHD ransomware and related families including BEAF, PXJ, ZZZZ, CHiCHi, and Tflower to DPRK-affiliated operators, with Trellix and Kaspersky linking the activity to Lazarus/APT38/Unit 180. The reporting says the campaigns were narrowly targeted, especially in the APAC region, and appeared aimed at revenue generation rather than mass extortion. Investigators cited shared code, overlapping artifacts, near-identical visual patterns, a reused ProtonMail address, and the use of the MATA framework as evidence that these ransomware strains were not typical criminal affiliate tools but part of a state-linked operation.
Kaspersky described two 2020 intrusions in which attackers exploited a vulnerable VPN gateway, escalated privileges, deployed MATA, seized Active Directory, and pushed VHD across victim networks within hours; another case used a custom SMB brute-force spreading tool with propagation over mounted shares and WMI. Separate research from Netlab 360 and VMware detailed Dacls, also known as MATA, as a cross-platform Lazarus-linked RAT for Windows and Linux that uses TLS and RC4-protected command-and-control, modular plugins, and infrastructure that remained active across more than 100 identified C2 servers. Earlier ESET analysis placed the activity within Lazarus’s broader pattern of combining espionage, sabotage, and financially motivated operations through multiple code-sharing development cells.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
25 events from the most recent confirmed update back to the earliest known activity.
Kaspersky documented a MATA-cluster campaign launched in mid-August 2022 that targeted more than a dozen corporations in Eastern Europe, especially defense and oil-and-gas organizations, and remained active until May 2023. The operation used spear-phishing and exploit chains to deploy new Windows and Linux MATA variants, including tooling for air-gapped environments, and was assessed as closely related to earlier Lazarus-attributed MATA activity.
The Dacls command-and-control indicators discovered by VMware began to be used by VMware endpoint products in September 2020.
In August 2020, VMware Threat Analysis Unit discovered Dacls command-and-control servers on the Internet by emulating the malware's protocol.
The first investigated VHD incident occurred in Europe between March and May 2020. Attackers used a custom spreading utility with victim-specific administrative credentials to brute-force SMB, copy VHD over mounted shares, and execute it via WMI.
VHD ransomware surfaced in March 2020 and was later widely attributed in the security industry to DPRK-linked operators. Trellix and Kaspersky both describe it as a narrowly used ransomware family tied to Lazarus-linked tooling.
In a second 2020 incident handled by Kaspersky, attackers exploited a vulnerable VPN gateway, gained administrative privileges, deployed the MATA backdoor, took over Active Directory, and spread VHD across the network in about 10 hours.
Trellix reports that one of the observed ransom payments was 2.2 BTC in mid-2020, worth about $20,000 at the time, illustrating the relatively small payments associated with these campaigns.
A suspicious ELF file was flagged by a threat monitoring system on 25 October 2019, leading researchers to identify a previously undisclosed cross-platform RAT they named Dacls.
In late 2019, 360 Netlab published technical details on Dacls, describing Windows and Linux variants and linking the malware to Lazarus with moderate confidence.
VMware states that the first artifacts of Dacls, also known as MATA, were observed around April 2018, indicating the framework was in use by that time.
McAfee reported the Turkish Bankshot spear-phishing campaign against Turkish financial institutions in March 2018, involving an HTTP backdoor that supported 27 commands.
The HaoBao bitcoin-stealing campaign was disclosed in early 2018 and attributed to Lazarus mainly through malicious document metadata and dropped implant filenames.
WannaCryptor.D, also known as WannaCry, launched on 12 May 2017 using the EternalBlue exploit and disrupted critical systems worldwide, including hospitals in the United Kingdom.
A beta WannaCryptor dropper named taskschs.exe was uploaded to VirusTotal on 10 February 2017 and contained a ransom payload named taskmsgr.exe.
Attacks against Polish banks were disclosed in February 2017 and linked to Lazarus through shared malware logic and the presence of an already Lazarus-attributed file on a victim system.
In late 2017, Lazarus conducted cryptocurrency-focused attacks that stole bitcoin from South Korean users and eventually hacked and bankrupted a South Korean cryptocurrency exchange.
In February 2016, attackers abused the SWIFT payment system to steal more than $80 million from Bangladesh's central bank. The activity was later linked by U.S. agencies to a North Korean actor dubbed Hidden Cobra.
ESET described a 2016 alpha WannaCryptor sample named hpmessage.exe observed in the %STARTUP% location, suggesting possible in-the-wild testing before later outbreaks.
Sony Pictures Entertainment was heavily damaged in a 2014 destructive cyberattack later described as Operation Blockbuster and attributed to Lazarus.
The 2013 DarkSeoul campaign was attributed to Lazarus and mainly targeted South Korea's financial sector.
Operation Troy ran from 2009 to 2012 and targeted South Korean armed forces and government organizations as a Lazarus cyber-espionage campaign.
ESET's VB2018 paper states that Lazarus Group activity can be traced back to 2009, marking the beginning of the group's documented operational history.
Trellix reported in 2026 that VHD shared code, artifacts, and operational characteristics with BEAF, PXJ, ZZZZ, and CHiCHi ransomware, and assessed with high confidence that these targeted ransomware families were tied to DPRK financial cyber operators such as APT38/Unit 180.
Over roughly two years of tracking, VMware identified 121 Dacls command-and-control servers and reported that multiple servers remained active even as overall active infrastructure declined.
Kaspersky concluded in 2021 that VHD was not a commercial off-the-shelf ransomware product and that, because MATA was believed to be Lazarus-owned, VHD was also owned and operated by the Lazarus Group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourceblogs.vmware.com
Open sourcesecurelist.com
Open sourceblog.netlab.360.com
Open sourcevirusbulletin.com
Open sourcesecurelist.com
Open sourcemedia.kasperskycontenthub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.