ESET reported that WinorDLL64, a backdoor delivered by the unusual Wslink loader, appears to be part of the Lazarus malware arsenal with low-confidence attribution to the North Korean threat group. The malware communicates over an already established TCP connection created by Wslink, collects detailed host information, manipulates files, executes commands including PowerShell, and manages processes and sessions. Researchers said Wslink is notable for operating as a server, executing received modules directly in memory, and accepting additional client connections, while the initial compromise vector remains unknown. Confirmed victims were identified in South Korea, with limited telemetry also seen in Central Europe, North America, and the Middle East.
The attribution rests on technical and operational overlaps with earlier Lazarus- and Hidden Cobra-linked activity, including similarities to the GhostSecret and Bankshot malware families, South Korean victimology, and matching PE rich-header development artifacts. McAfee previously described Operation GhostSecret as a global espionage campaign tied to Hidden Cobra that used implants such as Proxysvc, a covert SSL listener/downloader on port 443 designed to accept inbound command-and-control connections and support reconnaissance. The shared use of listener-style implants, code overlap, and development-environment fingerprints strengthens the assessment that WinorDLL64 supports follow-on intrusion activity such as reconnaissance and lateral movement within a broader North Korean cyber-operations toolkit.

Pull IOCs and campaign context straight into your stack.
12 events from the most recent confirmed update back to the earliest known activity.
ESET published an analysis of WinorDLL64 on February 23, 2023, describing it as a backdoor payload used by Wslink and attributing it with low confidence to Lazarus. The assessment was based on South Korean victimology and overlaps in code, behavior, and PE rich headers with GhostSecret and Bankshot-related samples.
ESET stated that it had previously uncovered the Wslink downloader/loader in 2021. The loader was notable for running as a server and executing received modules directly in memory.
On April 25, 2018, McAfee published its analysis of Operation GhostSecret and attributed the campaign with high confidence to Hidden Cobra. The report linked new implants and infrastructure to earlier Destover-era operations and said the infrastructure remained active.
McAfee said Proxysvc was first collected on March 22, 2018 from an unknown entity in the United States. The implant was described as a listener/downloader that accepts inbound connections on port 443.
McAfee reported that the Proxysvc dropper was submitted from South Korea on March 19, 2018. This was one of the early collection points for the undocumented implant.
McAfee observed Operation GhostSecret malware operating globally from March 18 to March 26, 2018. The campaign targeted sectors including critical infrastructure, finance, healthcare, telecommunications, and entertainment.
McAfee telemetry indicated Proxysvc components were active in the wild from March 16 to 21, 2018. The implant was seen mostly in higher education organizations across 11 countries.
McAfee reported that the 2018 Destover-like implant appeared in organizations in 17 countries between March 14 and March 18, 2018. This showed broad international spread early in the campaign.
McAfee said the February 2018 implant sample was obtained from an unknown submitter in the United States on February 14, 2018. The sample was later linked to Hidden Cobra tooling through code and artifact overlaps.
McAfee reported that a previously unknown data-gathering implant surfaced in mid-February 2018. It had capabilities similar to Bankshot but was not based on Bankshot.
McAfee assessed that the Proxysvc implant was used alongside a 2017 Destover variant and had operated undetected since mid-2017. This established an earlier lineage for tooling later tied to Operation GhostSecret.
ESET reported that a previously unknown Wslink payload was uploaded to VirusTotal from South Korea shortly after its earlier Wslink blog post. The uploaded payload matched an ESET YARA rule based on the unique name WinorDLL64.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcemcafee.com
Open sourcevirusbulletin.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.