DYEPACK is a malware framework used in financially motivated intrusions against banks and their SWIFT transaction infrastructure. It is associated with the North Korean state-sponsored threat actor APT38 and related activity tracked as Bluenoroff and TA444 within the broader Lazarus ecosystem. Deployed as post-exploitation tooling, DYEPACK can create, delete, and alter records in databases used for SWIFT transactions. This functionality compromises the integrity of banking transaction data and supports fraudulent financial operations. DYEPACK is also characterized as a SWIFT money-laundering framework. Its database manipulation behavior is mapped to MITRE ATT&CK Stored Data Manipulation (T1565.001).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT38 Bitsran BLINDTOAD BOOTWRECK Contopee DarkComet DYEPACK HOTWAX NESTEGG PowerRatankba REDSHAWL WORMHOLE Lazarus Group
Their collection of post-exploitation backdoors has included the msoRAT credential stealer, the SWIFT money laundering framework DYEPACK, and various passive backdoors and virtual "listeners" for receiving and processing data from target machines.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family associated with BlueNorOff operations.
Listed alongside the DYEPACK.FOX variant in the APT38 advisory; individual capabilities are not described.
A SWIFT money laundering framework used by TA444 in post-exploitation activity.
Post-exploitation backdoor used by TA444 historically.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.