Lazarus-linked operators exploited unpatched VMware Horizon servers vulnerable to Log4Shell (CVE-2021-44228) to compromise organizations, with reporting tying the activity to energy-sector victims in the United States, Canada, and Japan as well as broader targeting of Japanese entities. After initial access, the attackers deployed multiple backdoors and RATs including VSingle, YamaBot, MagicRAT, and NukeSped, then carried out hands-on-keyboard actions such as disabling security tools, creating unauthorized accounts, harvesting credentials, enumerating Active Directory, moving laterally with Windows administration utilities and Impacket, and exfiltrating selected files. Separate reporting also found the same exposed Horizon systems had been abused by other actors to install a Monero miner, underscoring how quickly internet-facing Log4Shell targets were reused.
The malware set showed a mix of Windows and Linux capability and several methods for blending command-and-control into normal web traffic. VSingle supported remote command execution and file transfer, and newer Linux variants could fall back to GitHub to retrieve replacement C2 addresses when hard-coded servers failed, using repository content to locate attacker infrastructure. YamaBot, a Golang backdoor for both Windows and Linux, exchanged RC4- and Base64-protected data through HTTP cookies and could disguise larger exfiltration as BMP-like multipart content, while NukeSped provided modular espionage functions including shell access, file management, keylogging, screen capture, and tunneling. Researchers attributed the campaign to Lazarus based on malware overlaps, infrastructure links, and tradecraft consistent with prior North Korean espionage operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos publicly attributed the February-to-July 2022 energy-sector intrusions to Lazarus with high confidence. The assessment was based on malware overlaps, infrastructure overlaps, and similarities to prior reporting and CISA advisories.
JPCERT/CC published analysis of YamaBot, a Golang backdoor used by Lazarus against both Windows and Linux systems. The report described its HTTP cookie-based C2 protocol, RC4-protected data exchange, and platform-specific command handling.
JPCERT/CC reported updated Linux-focused VSingle malware that retrieves replacement C2 information from attacker-controlled GitHub repositories when hard-coded C2 servers fail. The analysis also noted the Linux variant had shifted to using wget for network communications.
During the 2022 campaign, attackers exploited exposed VMware Horizon servers via Log4Shell and deployed Lazarus malware including VSingle, MagicRAT, and in some cases YamaBot. Talos also described hands-on-keyboard activity such as disabling Defender, reconnaissance, credential theft, lateral movement, and exfiltration.
Cisco Talos observed a Lazarus campaign between February and July 2022 targeting energy organizations, especially in the United States, Canada, and Japan. The intrusions aimed to establish long-term access and steal data for espionage purposes.
CVE-2021-44228 was publicly disclosed along with proof-of-concept material via Twitter and GitHub. This disclosure helped drive subsequent exploitation activity against exposed systems.
An initial patch for CVE-2021-44228 was released by Apache. The ASEC reference notes that additional patches followed afterward.
Alibaba’s cloud security team reported the Apache Log4j 2 vulnerability CVE-2021-44228 to the Apache Software Foundation. This was the earliest dated milestone cited for the Log4Shell issue later exploited in Lazarus activity.
JPCERT/CC published analysis of Lazarus operations targeting Japanese organizations using the VSingle and ValeforBeta malware families. The report detailed their HTTP-based C2 mechanisms, capabilities, and associated infrastructure.
ASEC found evidence that other attackers had previously exploited the same vulnerable system to deploy Jin Miner before Lazarus installed NukeSped. This showed the exposed VMware Horizon target had been compromised by multiple actors.
ASEC observed suspected Lazarus exploitation of unpatched VMware Horizon systems using Log4Shell in April. The attackers used PowerShell launched by VMware Horizon processes to install the NukeSped backdoor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourceblogs.jpcert.or.jp
Open sourceblogs.jpcert.or.jp
Open sourceasec.ahnlab.com
Open sourceblogs.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.