DICELOADER, also known as Lizar, IceBot, and Tirion, is a modular Windows backdoor associated with the financially motivated FIN7 threat group. Its minimal core establishes encrypted command-and-control communications and loads shellcode modules directly into memory, providing a foothold for post-exploitation and deployment of additional tooling. DICELOADER version 2.0 emerged in the first quarter of 2021 as an evolution and replacement of FIN7's earlier Carbanak command-and-control framework.
Its capabilities include harvesting browser-stored usernames and passwords, running Mimikatz to obtain credentials, collecting the current username and network configuration, and identifying antivirus-related processes. It can migrate its loader into another process and has used PowerShell scripts. DICELOADER has also delivered the NemesisProject backdoor framework.
FIN7 deploys DICELOADER through POWERTRASH, an obfuscated PowerShell loader that reflectively executes embedded payloads in memory. In intrusions against Veeam Backup & Replication servers, startup persistence for DICELOADER was established using POWERHOLD and DUBLOADER, which combined an autorun mechanism with DLL sideloading. DICELOADER has also served as a foothold in FIN7 operations preceding Cl0p ransomware deployment. It is a supporting intrusion tool rather than a ransomware payload itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exact method used by the threat actor to invoke the initial shell commands remains unknown but was likely achieved through a recently patched Veeam Backup & Replication vulnerability, CVE-2023-27532, which can provide unauthenticated access to a Veeam Backup & Replication instance. However, as there were no concrete indicators to confirm these findings, this remains a low-to-medium confidence assessment.
PaperCut servers vulnerable to CVE-2023-27350 implement improper access controls in the SetupCompleted Java class, allowing malicious actors to bypass user authentication and access the server as an administrator.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN7's use of POWERTRASH to deliver Lizar (aka DICELOADER or Tirion) was also highlighted by WithSecure.
The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.
An alleged FIN7 campaign, tracked as UNC4536 and UNC3319 by Mandiant, that distributed NetSupport RAT, possibly followed by DiceLoader or Carbanak.
An alleged FIN7 campaign, tracked as UNC4536 and UNC3319 by Mandiant, that distributed NetSupport RAT, possibly followed by DiceLoader or Carbanak.
...deploy the Lizar post-exploitation tool on compromised devices. This allowed the threat actors to gain a foothold within the targeted network and move laterally to deploy Clop ransomware...
28 distinct techniques documented for this family, organized by ATT&CK tactic.
86 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
59 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possible follow-on payload in a separate FIN7-linked campaign.
... Lizar ... (v1.0→v2.0) ...
Lizar (v1.0→v2.0)
A payload deployed by POWERTRASH in FIN7 intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.