#SIGNBT
Malware/Tool
SIGNBT is a Windows implant and backdoor used for victim control in Lazarus-associated operations against South Korean organizations. Documented versions include SIGNBT v0.0.1, a v1.2 HTTP implant, and Struggle, identified as SIGNBT 3.0. Its multi-stage execution chains abuse legitimate executables or DLL names, use DLL side-loading, decrypt staged payloads, and manually map PE files into memory; one chain launches through wsmprovhost.exe and mi.dll, while another uses mpev.dll, wpd.bin, and wpd.ini. Campaign delivery included compromised software or security products, watering holes, spear phishing, and vulnerability exploitation. Operation SyncHole placed SIGNBT in later attack phases alongside COPPERHEDGE, while other reporting describes its use for control after supply-chain compromise.
-
5
Tagged Reports
-
3
Unique Authors
-
1,008
Active Days