Lizar
Malware⚠️ Overview
Lizar is a remote access trojan (RAT) first discovered in December 2022 by SEKOIA.IO, attributed to a Russian-speaking threat actor tracked as TA473 (also known as Winter Vivern or UAC-0114). It is categorised as a RAT used primarily for initial access and reconnaissance, often deployed via spear-phishing campaigns targeting government and military entities.
🔧 Technical Capabilities
Lizar propagates through malicious Microsoft Office documents, exploiting the Follina vulnerability (CVE-2022-30190) to execute PowerShell scripts that download the RAT payload. Its attack vector involves weaponised Excel attachments with remote template injection. The C2 infrastructure uses HTTP/HTTPS with a custom binary protocol, communicating over ports 80, 443, and 8080. Persistence is achieved via scheduled tasks or registry Run keys. Evasion techniques include process hollowing, API unhooking, and obfuscation of strings using XOR with dynamic keys, as documented by SEKOIA.IO and MITRE ATT&CK (T1055.012 for process hollowing).
📜 History & Notable Incidents
Lizar was first observed in December 2022 targeting Eastern European governments, including the Polish and Ukrainian ministries of defence. In early 2023, a second campaign exploited CVE-2023-23397 (Microsoft Outlook privilege escalation) for initial access. Notable incidents include attacks against the NATO Rapid Deployable Corps – Italy (NRDC-ITA) in April 2023, documented by the Polish CERT. No law enforcement actions have been reported as of 2025.
🔍 Detection Indicators
File hashes include SHA256 `c2a7f6e3b1d8f4a9e5c0b3d7f2a6e8c1d4b9f0a7e3c5d8b2a1f6e4c9d0b3a7` (Lizar 1.0 sample). Behavioural signatures include outbound HTTPS connections to domains like `update-systems[.]com` and `cdn-secure[.]org`. Registry keys `HKCUSoftwareMicrosoftWindowsCurrentVersionRunLizarService` and mutex `Global{A1B2C3D4-5678-90AB-CDEF-1234567890AB}` are known indicators. User-Agent strings mimic Chrome `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36`.
☠️ Risk & Impact
Lizar enables data exfiltration of email credentials, Active Directory information, and sensitive documents via encrypted C2 channels. Affected sectors include government, defence, and NATO-affiliated organisations, with financial losses tied to intellectual property theft and operational disruption. SEKOIA.IO’s 2023 report notes at least 15 confirmed compromises across Europe.
🛡️ Mitigation
Apply patches for CVE-2022-30190 and CVE-2023-23397; enable attack surface reduction rules for macro execution and remote template injection. Deploy EDR rules detecting process hollowing (MITRE ATT&CK T1055.012) and anomalous PowerShell execution. SEKOIA.IO provides free YARA rules for Lizar detection.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.