logo

Lazarus_Group__2023__ESET_WinorDLL64-Lazarus-arsenal_02-23-2023.pdf

ID: 60f2147b-09db-47ff-bb42-4f2bcbeb591a

STIX ID: report--60f2147b-09db-47ff-bb42-4f2bcbeb591a

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2023-02-28

Last Modified Date: 2023-02-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers analyzed WinorDLL64, a DLL backdoor delivered by the Wslink loader that provides extensive system reconnaissance, file exfiltration/manipulation, process control, and remote command execution over an existing encrypted channel; the analysis includes code/behavior overlaps with known Lazarus samples (low-confidence attribution), technical details of commands and communication, IoCs (SHA-1), and MITRE ATT&CK technique mappings.