ThreatNeedle is a Windows backdoor associated with the Lazarus Group and used in cyberespionage operations, particularly against defense-sector organizations. It has also been linked through code and infrastructure overlaps to broader Lazarus activity clusters including Manuscrypt and CookieTime, and later reporting noted reuse in financially motivated Lazarus-affiliated operations targeting cryptocurrency organizations in South Korea. ThreatNeedle has been observed as a more sophisticated Lazarus trojan/backdoor variant and is commonly discussed as part of the group’s post-2018 tooling ecosystem.
ThreatNeedle is designed for covert remote access and in-memory execution. Reported behavior includes loading and running in memory, registering payloads as Windows services for persistence, and storing RC4-encrypted configuration data in the Windows Registry. In some intrusion chains it has been injected into legitimate Windows processes via shellcode, reflecting an emphasis on stealth and defense evasion.
Initial access has been tied to social engineering. ThreatNeedle has been delivered through spearphishing emails carrying malicious Word documents and relies on victim execution of the lure document. It has also been reported in a watering-hole operation against South Korean industrial organizations, where Lazarus exploited vulnerabilities in local software as part of Operation SyncHole.
ThreatNeedle is primarily associated with espionage-oriented targeting of the defense industry, including enterprises in multiple countries, though related Lazarus operations and code reuse connect it to later financially motivated campaigns as well. Its role in Lazarus operations, combined with overlaps in malware logic, communications patterns, and command-and-control scripting, makes it a notable representative of the group’s modular Windows intrusion tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently, a more sophisticated form of this trojan called ThreatNeedle surfaced as part of a cyberespionage campaign by Lazarus.
Malware ThreatNeedle Lazarus RAT used in espionage, reused by TraderTraitor in South Korea.
“In its more recent campaigns it has started deploying a new malware we call ThreatNeedle.”
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware being delivered through phishing or spearphishing emails containing malicious attachments such as Microsoft Office documents, PDFs, RAR/ZIP archives, CHM, ISO, IMG, HTA, LNK, and executable files disguised as documents.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples include: “ComRAT has encrypted and stored its orchestrator code in the Registry…”, “ShadowPad maintains a configuration block and virtual file system in the Registry.”, and “QakBot can store its configuration information…under HKCU\Software\Microsoft.”
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
RedCurl mimicked legitimate file names and scheduled tasks, e.g. MicrosoftCurrentupdatesCheck and MdMMaintenenceTask to mask malicious files and scheduled tasks.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
MITRE ATT&CK Mapping ... T1071.001 Application Layer Protocol: Web Protocols Use HTTP as C2 channel with backdoor
"LPEClient is a tool known for victim profiling and payload delivery (T1105)..."; "...Innorix abuser is used for lateral movement. It is downloaded by the Agamemnon downloader (T1105)..."
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus 관련 인프라 연관성 설명을 위해 언급된 악성코드다.
Referenced as Lazarus-associated malware in a comparison of overlapping infrastructure; no direct role in the main Xctdoor campaign described here.
Malware used in Lazarus Group's Operation SyncHole targeting South Korean firms; details not provided in the excerpt.
Named malware/cluster identified as part of the expanding Lazarus umbrella structure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.