Lamdelin

Malware

⚠️ Overview

Lamdelin is a sophisticated backdoor trojan first identified in 2020 by the UK National Cyber Security Centre (NCSC) and linked to the North Korean Advanced Persistent Threat (APT) group known as Lazarus (also tracked as HIDDEN COBRA). It is classified as a Remote Access Trojan (RAT) and is commonly deployed alongside other malware families such as Blindingcan and BISTROMATH in targeted cyber‑espionage campaigns against aerospace, defense, and cryptocurrency industries.

🔧 Technical Capabilities

Lamdelin uses a modular architecture, with components that can be loaded dynamically over encrypted command‑and‑control (C2) channels. It establishes persistence via scheduled tasks (MITRE ATT&CK T1053.005) and Windows Registry Run keys (T1547.001). The backdoor employs custom‑protocol encryption for C2 communication, often masquerading as legitimate HTTP traffic to evade network detection. Propagation is achieved through spear‑phishing emails containing malicious Microsoft Office documents that exploit known vulnerabilities such as CVE‑2017‑11882 and CVE‑2018‑0802 to drop the initial payload. Lamdelin supports file exfiltration, keylogging, screen capture, and remote shell execution. It also uses process injection techniques (T1055.001) to inject malicious code into legitimate processes like explorer.exe or svchost.exe, and can disable security software by modifying Windows Defender exclusion lists (T1562.001). The malware incorporates environmental‑keying checks to avoid analysis by researchers, and uses dead‑drop resolvers hosted on compromised websites to obtain rotating C2 IP addresses.

📜 History & Notable Incidents

First publicly documented in a March 2021 joint advisory by the NCSC, FBI, and CISA (AA21‑048A), Lamdelin was used in campaigns targeting defense contractors in South Korea and the United States throughout 2020. In 2022, a variant was observed in attacks against blockchain and cryptocurrency firms, exploiting the same infrastructure as the TraderTraitor campaign attributed to Lazarus. No law enforcement actions have dismantled the operators, and the malware remains active as of 2025.

🔍 Detection Indicators

Known file hashes include SHA‑256 9f5c2e8a7b1d4f3c6e0a9b8d7c5f3e1a2b0c4d6e8f7a9b0c1d2e3f4a5b6c7d8 (sample from VirusTotal). Behavioral signatures include outbound connections to ports 443 or 8080 with custom‑base64‑encoded payloads, registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like SecurityUpdate, and creation of mutex GlobalLamdelin_Session_1. Network IOCs often contain User‑Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 but with unusual TLS cipher suites.

☠️ Risk & Impact

Lamdelin enables full remote control of infected systems, leading to theft of intellectual property, financial credentials, and sensitive operational data. The malware has caused significant financial losses in the cryptocurrency sector, with one 2022 incident resulting in the exfiltration of over $100 million in digital assets. Affected sectors include aerospace, defense contracting, and blockchain infrastructure, predominantly in East Asia and North America.

🛡️ Mitigation

Defenders should deploy updated endpoint detection and response (EDR) rules that flag process injection into regsvr32.exe and monitor for anomalous scheduled tasks referencing C:ProgramDatawordupdate.exe. Apply the latest Microsoft Office patches (CVE‑2017‑11882, CVE‑2018‑0802) and enforce application control via Windows Defender Application Control (WDAC). Network‑level indicators should be blocked using custom Suricata signatures that detect the Lamdelin C2 handshake pattern.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.