#LPEClient

Malware/Tool

2021-12-21 • Multi-universe of adversary: Multiple campaigns of Lazarus group and its connect

LPEClient is a Lazarus-associated tool used for victim profiling and payload delivery in targeted operations against defense contractors and the cryptocurrency industry. It has been observed in memory alongside the SIGNBT malware after attackers compromised a software vendor through trusted security software used for encrypted web communications. Other activity showed a ThreatNeedle variant loading LPEClient directly. Across these campaigns, LPEClient served as a modular reconnaissance and delivery component that helped operators assess compromised hosts and introduce additional payloads.

Tagged Reports

« Back