#LightlessCan

Malware/Tool

2023-09-29 • Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company

LightlessCan is a previously undocumented backdoor deployed by Lazarus during a cyberespionage intrusion at a Spanish aerospace company. After the victim ran the files on a corporate device, Lazarus deployed a multi-tool infection chain whose principal payload was LightlessCan. The backdoor included techniques intended to hinder detection by real-time security monitoring and complicate analysis, including behavior designed to prevent execution on selected systems such as security researchers’ machines.

Tagged Reports

« Back