NukeSped is a Lazarus-associated backdoor and remote access trojan family used in multiple espionage and financially motivated intrusion sets. It has been observed across Windows, macOS, and Android, with reporting also referencing Linux-targeting activity in Lazarus campaigns where NukeSped-related tooling or closely aligned implants were deployed. Security vendors commonly treat NukeSped as a signature Lazarus malware family, and it has appeared in operations targeting South Korean public institutions, universities, logistics, IT, manufacturing, defense-related organizations, and cryptocurrency-focused victims.
NukeSped provides remote control of infected systems through command-and-control tasking. Documented capabilities include shell command execution, file management, system information collection, keylogging, screen capture, port forwarding, SOCKS-style proxying or tunneling, process termination, and in some variants process injection. Some samples support self-deletion and persistence through service-based or launcher-assisted mechanisms. Windows variants have been observed as staged payloads that drop packed loaders and service components, while macOS variants have appeared both as standalone trojans and as components in trojanized application chains. Android detections under the NukeSped naming convention have also been reported by vendors.
The malware family uses multiple communication patterns depending on variant. Reported implementations include raw TCP backdoors with custom authentication exchanges and RC4- or DES-protected traffic, HTTP POST-based initial communications, and HTTP-like fake protocol strings intended to resemble SSL or web traffic. Lazarus-linked NukeSped development has also shown recurring anti-analysis and evasion traits, including encrypted strings, custom packers, garbage API insertion, dynamic API resolution, anti-sandbox checks, and self-deleting batch-script logic.
Observed delivery and installation chains include spearphishing documents with malicious macros, watering-hole compromises exploiting vulnerable software, supply-chain style delivery through trojanized software or packages, and staged downloaders that retrieve NukeSped as a later payload. In more recent Lazarus activity, NukeSped has also appeared as a follow-on Windows payload in broader cross-platform credential-theft and remote-control campaigns. The family is closely associated with Lazarus and, in some reporting, with Andariel or Bluenoroff activity where operational overlap or subgroup ambiguity exists.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability... | ASEC has revealed attack cases where the Lazarus group used the vulnerability to spread NukeSped in 2022.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In a Lazarus attack campaign captured by ThreatBook in the second half of 2025, the Nukesped trojan drop path was /Library/Caches/System Settings — consistent with the trojan drop directory in this supply chain poisoning incident.
`dropper.vb_s` (named as we obtained it), 497-line VBScript implant classified as Trojan.NukeSped, a known Lazarus Group malware family.
Over the last 15 years, the group has developed RATs, including the following... ▪ NukeSped
744 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus-linked VBScript implant/backdoor fetched by the PowerShell loader on Windows; it collects system data, browser extensions, and signs of Telegram use, then retrieves additional payloads while attempting to weaken local defenses.
NukeSped is referenced in connection with a DPRK BlueNoroff ClickFix kit, implying it is malware associated with that campaign/tooling.
A VBScript-based C2 implant used in the fake meeting lure infection chain on Windows. It supports command-and-control activity, checks for Telegram Web artifacts, inventories browser extensions including wallet-related ones, and may enable in-memory execution or additional payload delivery.
A Lazarus/BlueNoroff-linked VBScript C2 implant used in the campaign’s Windows chain. It performs host reconnaissance, process and browser-extension enumeration, optional Telegram Web usage checks, beacons to C2, and supports fileless execution or disk-dropped follow-on payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.