Lazarus_Group__2021__Are_you_afreight_of_the_dark_Watch_out_for_Vyveva_new_Lazarus_backdoor_WeLiveSecurity.pdf
ID: 3dc57ce6-ed45-498a-bd6e-26450a26ec2f
STIX ID: report--3dc57ce6-ed45-498a-bd6e-26450a26ec2f
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2021-04-09
Last Modified Date: 2021-04-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers disclose and analyze Vyveva, a Lazarus-linked backdoor used since at least 2018 to target a freight logistics company in South Africa; the report describes installer/loader/backdoor components, Tor-based C2, file-exfiltration, timestomping and watchdog features, lists IoCs (sample hashes, filenames), and maps observed behavior to MITRE ATT&CK techniques.
