#Comebacker
Malware/Tool
2024-02-21 • PyPIを悪用した攻撃グループLazarusのマルウェア拡散活動
Comebacker is a Lazarus-associated Windows downloader and backdoor that retrieves DLL payloads from command-and-control servers and executes them. A 2025 variant was delivered through files disguised as DOCX documents using aerospace and defense themes, while earlier distribution placed an XOR-encoded DLL inside malicious PyPI packages. In that package chain, the DLL was decoded, saved as output.py, launched with rundll32, and used staged files including IconCache.db and NTUSER.DAT, with the final component decoded and run in memory. Samples communicated with C2 through HTTP POST requests. Reporting traces the family to attacks on security researchers first publicized in 2021.
-
5
Tagged Reports
-
3
Unique Authors
-
626
Active Days