#YamaBot
Malware/Tool
YamaBot is a Go-based, multiplatform malware family used by Lazarus, with distinct Linux and Windows builds whose functions differ slightly. In a 2022 campaign against energy providers in the United States, Canada, Japan, and elsewhere, operators exploited VMware Horizon vulnerabilities for initial access and then deployed YamaBot alongside VSingle and MagicRAT to establish long-term access and exfiltrate information. YamaBot communicates with its command-and-control server through HTTP requests. Function names recovered from the Windows sample indicate host and operating-system discovery, MAC and IP address collection, mutex creation and checking, random-string and hash utilities, command execution, and HTTP POST routines capable of handling cookies and files.
-
3
Tagged Reports
-
3
Unique Authors
-
71
Active Days