Lazarus_Group__2023__ESET_WinorDLL64-Lazarus-arsenal_02-23-2023.pdf
ID: 60f2147b-09db-47ff-bb42-4f2bcbeb591a
STIX ID: report--60f2147b-09db-47ff-bb42-4f2bcbeb591a
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2023-02-28
Last Modified Date: 2023-02-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers analyzed WinorDLL64, a DLL backdoor delivered by the Wslink loader that provides extensive system reconnaissance, file exfiltration/manipulation, process control, and remote command execution over an existing encrypted channel; the analysis includes code/behavior overlaps with known Lazarus samples (low-confidence attribution), technical details of commands and communication, IoCs (SHA-1), and MITRE ATT&CK technique mappings.
