#Wslink
Malware/Tool
2023-02-23 • WinorDLL64: A backdoor from the vast Lazarus arsenal?
Wslink is a Windows loader that operates as a server on an already compromised host and executes received modules directly in memory. Unlike a typical downloader that initiates an outbound payload fetch, it accepts and loads modules over an established connection. Its known WinorDLL64 payload collects extensive system information, manipulates files by exfiltrating, overwriting, or deleting them, and executes additional commands while reusing the loader’s connection. Code and behavioral overlap led ESET to associate the tool with Lazarus.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days