#Vyveva

Malware/Tool

2021-04-08 • (Are you) afreight of the dark? Watch out for Vyveva, new Lazarus backdoor

Vyveva is a multicomponent Lazarus backdoor discovered on two servers belonging to a freight-logistics company in South Africa, indicating targeted deployment. The Windows-oriented toolset includes an installer, loader, main backdoor payload, and TorSocket DLL. It communicates with command-and-control infrastructure through the Tor network using fake TLS, creates a Windows service for loader persistence, and stores its default encrypted configuration in the registry. The backdoor supports remote tasking, file operations, process management, system reconnaissance, and timestamp manipulation.

Tagged Reports

« Back