SIGNBT is a Lazarus-associated Windows backdoor used in multi-stage intrusions against organizations in South Korea and in operations linked to the TraderTraitor cluster. It has been observed as an in-memory initial implant and as part of watering-hole exploitation chains that abused vulnerabilities in widely deployed South Korean financial and security software. In these campaigns, compromised legitimate websites selectively redirected targets to exploit content that triggered remote code execution through local software components, after which SIGNBT or the related COPPERHEDGE backdoor was loaded without requiring a conventional download prompt. SIGNBT has also been reported in Lazarus operations targeting software vendors and in updated TraderTraitor activity.
Operationally, SIGNBT is used to establish covert control of compromised systems and to stage follow-on malware. Documented variants include early builds such as version 0.0.1 and later versions such as 1.2 and 3.0 mappings reported by defenders. Version 0.0.1 was observed executing in memory inside a legitimate Windows process to fetch additional malware, while later variants were described as focused on executing additional payloads. Across reporting, SIGNBT supports remote command execution, delivery of further implants, file theft, internal reconnaissance, and process injection. Some intrusion chains stored encrypted configuration data in the Windows registry and decrypted later stages only in memory, reflecting a fileless or low-artifact design intended to reduce forensic visibility.
The malware’s tradecraft is consistent with Lazarus tooling. Analysts have noted use of TLS callbacks as an evasion mechanism also seen in other Lazarus families, as well as recurring in-memory PE loading and overlap with DLL sideloading-centric execution chains in adjacent malware clusters. In South Korean watering-hole operations, payloads associated with SIGNBT were injected into legitimate Microsoft processes, and subsequent activity included privilege escalation, credential access tooling, and lateral movement by the operators. SIGNBT therefore functions less as a standalone end-state payload than as a stealthy foothold and execution platform within broader espionage and financially motivated campaigns.
Victimology tied to SIGNBT includes South Korean software, IT, financial, semiconductor manufacturing, telecommunications, healthcare, education, manufacturing, and news-related environments reached through compromised trusted websites and local software exploitation. Its association with Lazarus and TraderTraitor places it within a broader ecosystem of North Korean operations spanning espionage, supply-chain compromise, and cryptocurrency-focused intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. | A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or user-initiated download.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in the watering-hole campaign to provide remote command execution, file theft, internal reconnaissance, process injection, and delivery of additional payloads. Reports also describe DLL side-loading, encrypted registry blobs, and in-memory PE loading across SIGNBT clusters.
Named malware cluster referenced in a post linking to an analysis by S2W; the post indicates it is fileless malware.
Referenced as a Lazarus malware/tool family associated with TLS callback anti-analysis and custom cryptography tradecraft.
SIGNBT is referenced as a Lazarus tool family exhibiting similar TLS callback anti-analysis behavior to the analyzed loader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.