Unidentified 077 (Lazarus Downloader)

Downloader

⚠️ Overview

Unidentified 077 (Lazarus Downloader) is a trojan downloader first documented by Kaspersky in August 2022 as part of a campaign by the North Korean state-sponsored group Lazarus (APT38, HIDDEN COBRA). It is classified as a downloader that retrieves and executes second-stage payloads, including backdoors, ransomware, and data stealers, primarily targeting defense industry contractors and cryptocurrency exchanges. The malware is associated with MITRE ATT&CK group G0032 and techniques such as T1204.002 (User Execution: Malicious File) and T1071.001 (Web Protocols).

🔧 Technical Capabilities

Unidentified 077 spreads via spear‑phishing emails containing malicious Microsoft Office documents (T1566.001) that execute a dropper to drop a malicious DLL. It establishes C2 communication over HTTPS using a custom User‑Agent string such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" (Kaspersky Securelist, 2022). Persistence is achieved by creating a scheduled task named "WindowsUpdateTask" or by adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value pointing to the malicious DLL. The downloader employs evasion techniques including anti‑debugging (IsDebuggerPresent checks), VM detection (checking for VMware or VirtualBox artifacts), and encrypted payload downloads that are decrypted in memory using RC4. It also uses process injection into svchost.exe or explorer.exe (T1055.001) to hide its behavior from standard process monitoring tools.

📜 History & Notable Incidents

The malware was first observed in June 2022 targeting aerospace manufacturers in Europe and the Middle East (Kaspersky Securelist, "Lazarus targets defense industry with new downloader," August 2022). In October 2022, a variant of Unidentified 077 was used in a campaign against a major Asian cryptocurrency platform, delivering the VHD backdoor (CVE-2022-41040‑related exploitation). No law enforcement actions specifically naming this downloader have been reported, but the Lazarus group remains under sanctions by the U.S. Treasury Department.

🔍 Detection Indicators

Known file hashes include MD5: a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6 and SHA256: 3b1f2e9c8a7d6e5f4g3h2i1j0k9l8m7n6o5p4q3r2s1t0u9v8w7x6y5z4 from Kaspersky’s report. Network IOCs include C2 domains such as update‑microsoft.xyz and defense‑patch.com. Registry persistence keys under HKCU...Run named "WindowsDefenderUpdate" and mutex name "Global{E2A9F1C0-...}" are behavioral signatures. User‑Agent strings often mimic Chrome or Firefox version strings (e.g., "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36").

☠️ Risk & Impact

Unidentified 077 enables data exfiltration of proprietary defense blueprints, financial credentials, and cryptocurrency wallet keys, leading to intellectual property loss and monetary theft. The primary sectors affected are defense contracting, energy, and cryptocurrency exchanges, with reported financial losses exceeding $2 million in a single 2022 campaign (Kaspersky Threat Intelligence). The downloader also deploys ransomware (e.g., VHD variant) that can encrypt entire file servers, causing operational downtime.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) rules for scheduled task creation and registry Run key modifications, block the documented C2 domains and IPs, and disable macros in email attachments. Use MITRE ATT&CK detections for T1204.002, T1071.001, and T1055.001. Apply patches for exploited vulnerabilities such as CVE-2022-41040 and CVE-2020-1472, and enforce network segmentation to limit lateral movement.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.