The Lazarus Injector

2019-07-22 • Norfolk •

https://norfolkinfosec.com/the-lazarus-injector/

Thumbnail for The Lazarus Injector

The Lazarus Injector analysis covers a DPRK SWIFT-heist-related tool used to load a supplied payload into explorer.exe. The injector validates command-line parameters and payload file access, enumerates processes to locate Explorer, allocates remote memory, writes the payload, and starts execution through resolved APIs. Optional parameters control sleep and cleanup behavior, including overwriting and deleting the original payload from disk. The report provides hashes and behavioral details useful for detecting Lazarus loader activity rather than relying on a long indicator list alone.

Indicators of Compromise

Type Value First Seen Last Seen
HASH db0f102af2d350aa1a63772e6ee9b21… 2019-07-22 2020-08-05

Related Actors

Related Reports

« Back