#Vyveva
Malware/Tool
2021-04-08 • (Are you) afreight of the dark? Watch out for Vyveva, new Lazarus backdoor
Vyveva is a multicomponent Lazarus backdoor discovered on two servers belonging to a freight-logistics company in South Africa, indicating targeted deployment. The Windows-oriented toolset includes an installer, loader, main backdoor payload, and TorSocket DLL. It communicates with command-and-control infrastructure through the Tor network using fake TLS, creates a Windows service for loader persistence, and stores its default encrypted configuration in the registry. The backdoor supports remote tasking, file operations, process management, system reconnaissance, and timestamp manipulation.
-
2
Tagged Reports
-
2
Unique Authors
-
328
Active Days