#Volgmer

Malware/Tool

2014-12-04 • Destover: Destructive malware has links to attacks on South Korea

Volgmer is a Windows backdoor used by Lazarus and documented in multiple generations, with early samples installed through a dropper and later versions showing continued development. It supports persistent remote access in campaigns where Lazarus disguised malicious components as legitimate programs and targeted defense, technology, finance, and South Korean organizations. Reporting analyzes it alongside the Scout downloader and traces changes between early and later backdoors. MITRE ATT&CK S0180.

Tagged Reports

« Back