logo

Lazarus_Group__2021__Are_you_afreight_of_the_dark_Watch_out_for_Vyveva_new_Lazarus_backdoor_WeLiveSecurity.pdf

ID: 3dc57ce6-ed45-498a-bd6e-26450a26ec2f

STIX ID: report--3dc57ce6-ed45-498a-bd6e-26450a26ec2f

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2021-04-09

Last Modified Date: 2021-04-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers disclose and analyze Vyveva, a Lazarus-linked backdoor used since at least 2018 to target a freight logistics company in South Africa; the report describes installer/loader/backdoor components, Tor-based C2, file-exfiltration, timestomping and watchdog features, lists IoCs (sample hashes, filenames), and maps observed behavior to MITRE ATT&CK techniques.