DiceLoader, also known as Lizar, Tirion, and IceBot, is a FIN7-associated Windows backdoor used as a lightweight post-compromise implant and staging component. It is regarded as part of the evolution of FIN7’s tooling after Carbanak, with reporting describing DiceLoader as a minimal backdoor that establishes an encrypted command-and-control channel and supports in-memory loading of additional modules or payloads. It has been used in FIN7 intrusions alongside PowerShell-based tooling such as POWERTRASH and has also been observed as a delivery mechanism for follow-on frameworks including NemesisProject. Reporting further links it to exploitation chains involving vulnerable internet-facing software and to broader FIN7 intrusion activity targeting financially motivated objectives.
Functionally, Lizar/DiceLoader supports host profiling and post-exploitation tasks. Documented capabilities include collecting the current username, retrieving local network configuration information, enumerating security software or antivirus-related processes, harvesting usernames and passwords stored in browsers, retrieving browser history and browser database artifacts, executing PowerShell scripts, and migrating or injecting itself into another process. Its role is therefore not limited to simple beaconing; it acts as a compact foothold that can support reconnaissance, credential access, defense evasion, and delivery of additional tooling.
DiceLoader is most strongly associated with FIN7, a long-running Russian-speaking cybercriminal group known for financially motivated intrusions against sectors including retail, hospitality, restaurants, finance, technology, and other enterprises. Within that ecosystem, DiceLoader has been described as part of FIN7’s dedicated arsenal and as a successor or replacement direction relative to older Carbanak-era tooling. It has also appeared in campaigns tracked under UNC designations attributed to alleged FIN7 activity, including operations that distributed remote-access tooling and potentially followed with DiceLoader or Carbanak.
The malware targets Windows environments and is typically used after initial compromise rather than as a self-contained mass-distribution stealer. Observed delivery and execution chains include PowerShell-based loaders and exploitation of exposed enterprise software, after which DiceLoader provides a resilient foothold for follow-on intrusion activity, credential theft, and deployment of additional payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-27350. This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF and enables an unauthenticated actor to execute malicious code remotely without credentials. | The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...and malware acquired from FIN7 developers such as Minodo and Diceloader.
An alleged FIN7 campaign, tracked as UNC4536 and UNC3319 by Mandiant, that distributed NetSupport RAT, possibly followed by DiceLoader or Carbanak.
An alleged FIN7 campaign, tracked as UNC4536 and UNC3319 by Mandiant, that distributed NetSupport RAT, possibly followed by DiceLoader or Carbanak.
The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.
...deploy the Lizar post-exploitation tool on compromised devices. This allowed the threat actors to gain a foothold within the targeted network and move laterally to deploy Clop ransomware...
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
crypters, which are also referred to as loaders or packers, are applications designed to encrypt and obfuscate malware to evade detection by antivirus (AV) scanners and hinder analysis.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Powertrash, a heavily obfuscated PowerShell script, is designed to reflectively load an embedded PE file in-memory... The payload is not designed to be dropped directly on the disk and is compiled with the ReflectiveLoader implementation to allow in-memory reflective loading.
Multiple actors and tools are described as using Mimikatz/Windows Credential Editor/LaZagne/ProcDump to “dump credentials,” often by targeting LSASS memory (e.g., “used Mimikatz to capture and use legitimate credentials,” “dumped the LSASS process memory using the MiniDump function,” “injecting itself into lsass.exe”).
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons... Associated with TrueBot C2... Associated with Cobalt Strike Beacon.
À l’issue du processus de recrutement, des outils d’intrusion sont fournis au candidat, parmi lesquels... Carbanak et Lizar...
“APT29 has used multiple layers of encryption within malware to protect C2 communication… BITTER has encrypted their C2 communications… Emotet has encrypted data before sending to the C2 server… gh0st RAT has encrypted TCP communications to evade detection… Gomir uses a custom encryption algorithm…”
85 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possible follow-on payload in a separate FIN7-linked campaign.
... Lizar ... (v1.0→v2.0) ...
Lizar (v1.0→v2.0)
A payload deployed by POWERTRASH in FIN7 intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.