Public research described a Windows shellcode execution method linked to Lazarus Group that stores payloads as UUID-formatted strings, decodes them with the Windows API UuidFromStringA, and writes the resulting bytes directly into executable memory. A proof of concept showed the payload being reconstructed after memory allocation with VirtualAlloc, while related reporting said Lazarus used HeapCreate and HeapAlloc in observed operations.
The reconstructed shellcode was then executed indirectly through callback-based Windows APIs, including EnumChildWindows and EnumDesktopsA, while separate analysis associated Lazarus with using EnumSystemLocalesA for the same purpose. The technique highlights a stealth-oriented approach that blends payload decoding with legitimate system functions to launch in-memory code and reduce straightforward static detection.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
A cocomelonc post published a Windows proof of concept that decodes UUID-formatted payload chunks with UuidFromStringA into executable memory and runs them via callback APIs such as EnumChildWindows. The post states the approach is similar to a method associated with Lazarus Group and includes code and a helper script for converting payloads into UUID strings.
NCC Group RIFT published research analyzing a shellcode execution method associated with Lazarus Group. The later cocomelonc article explicitly references this NCC Group analysis as the basis for the described technique.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.