NukeSped is a remote access trojan and backdoor family associated with the North Korean Lazarus Group and its Andariel-linked operations. The name is also used by antivirus vendors to classify a broad range of Lazarus malware, so individual variants differ substantially in architecture and functionality. Identified variants include Windows and macOS malware, with Android samples also classified under the NukeSped detection name. Documented deployments have targeted South Korean public institutions, universities, and organizations in logistics, information technology, manufacturing, telecommunications, and semiconductor production.
NukeSped provides attacker-controlled command execution, file management and transfer, additional payload downloading, process termination, and host reconnaissance. More capable variants support keylogging, screenshot capture, data exfiltration, SOCKS tunneling, and port forwarding. Some Windows variants inject code into legitimate processes, load payloads directly into memory, or operate through service-based deployment chains.
Infection chains include phishing and spearphishing attachments containing malicious Word macros, as well as watering-hole attacks exploiting vulnerable software. Macro-based chains can reconstruct executable content from embedded images and abuse Windows management and scripting utilities to launch intermediate loaders. NukeSped has also been deployed following Log4Shell exploitation of unpatched VMware Horizon servers.
Command-and-control implementations vary between custom raw TCP protocols and HTTP-based exchanges. Variants use encrypted strings, dynamic API resolution, and RC4, DES, or XOR-based protection. Some disguise command traffic and results as ordinary web requests. Defense-evasion features include encrypted packing, anti-debugging and sandbox checks, in-memory execution, and self-deletion; certain variants remove themselves when command-and-control communication fails.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ASEC identified attacks against vulnerable Apache ActiveMQ servers and suspected Andariel exploited CVE-2023-46604 to install NukeSped and TigerRat. Direct logs proving the NukeSped installation occurred through this vulnerability were unavailable.
The new variants of the NukeSped malware are exploiting the recently release Log4shell vulnerability in unpatched VM horizon servers since January 2022. | The NukeSped malware is a remote access trojan (RAT) and has been attributed to the threat actor Lazarus Group.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Although there were no direct logs showing that NukeSped was installed through exploitation of the CVE-2023-46604 vulnerability, there is a possibility that the Andariel group exploited CVE-2023-46604 vulnerability for the attack.
Although there were no direct logs showing that NukeSped was installed through exploitation of the CVE-2023-46604 vulnerability, there is a possibility that the Andariel group exploited CVE-2023-46604 vulnerability for the attack.
`dropper.vb_s` (named as we obtained it), 497-line VBScript implant classified as Trojan.NukeSped, a known Lazarus Group malware family.
Over the last 15 years, the group has developed RATs, including the following... ▪ NukeSped
37 distinct techniques documented for this family, organized by ATT&CK tactic.
NukeSped에서는 지속성 유지를 위한 기능이 존재하지 않기 때문에 직접 커맨드 라인 명령을 이용해 작업 스케줄러에 등록시키는 명령들도 확인된다.
The threat actor runs a power-shell script to exploit the Log4j vulnerability and installs the NukeSped on the victim machine.
The first payload is used to run the command prompt to execute file “edg89C0.bat” and finally drop and execute the 2nd stage payload.
매크로 실행 시 악성 행위가 시작됨과 동시에 정상 문서 내용을 출력한다... 악성 매크로는 이미지 변환 기법을 사용하여 악성 PE 바이너리를 로드한다.
The strings and important API calls are encoded with base64 and RC4 encrypted.
Dynamic resolution of Windows APIs ... The technique is very typical and has already been described [2, p.59].
cmd.exe /c "ipconfig /all" ... cmd.exe /c "netstat -naop tcp"
감염된 시스템의 사용자 이름, 컴퓨터 이름, MAC 및 IP 정보 등 기본적인 정보를 Base64 인코딩하여 ... C&C 서버에 전송한다.
ProtocolTcpPure 클래스를 보면 알 수 있듯이 Raw TCP 프로토콜을 이용해 C&C 서버와 통신한다.
ModuleSocksTunnel 클래스에서는 이름과 같이 터널링 기능을 제공할 것으로 추정된다... C&C 서버와 해당 주소 간의 프록시로서 동작한다.
ModulePortForwarder 클래스에서는 이름과 같이 포트 포워딩 기능을 지원한다... 외부에 존재하는 공격자는 포트 포워딩 기능을 지원하는 NukeSped를 통해 감염 시스템 내부 즉 사설 네트워크에 존재하는 공격 대상과 통신했을 것으로 추정된다.
749 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus-linked VBScript implant/backdoor fetched by the PowerShell loader on Windows; it collects system data, browser extensions, and signs of Telegram use, then retrieves additional payloads while attempting to weaken local defenses.
NukeSped is referenced in connection with a DPRK BlueNoroff ClickFix kit, implying it is malware associated with that campaign/tooling.
A VBScript-based C2 implant used in the fake meeting lure infection chain on Windows. It supports command-and-control activity, checks for Telegram Web artifacts, inventories browser extensions including wallet-related ones, and may enable in-memory execution or additional payload delivery.
A Lazarus/BlueNoroff-linked VBScript C2 implant used in the campaign’s Windows chain. It performs host reconnaissance, process and browser-extension enumeration, optional Telegram Web usage checks, beacons to C2, and supports fileless execution or disk-dropped follow-on payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.