Lurk is a Windows malware family best known as a downloader used to retrieve and execute secondary payloads, and it has also been described in some reporting as a banking trojan associated with financially motivated attacks on banks, particularly in Russia. The malware has been linked to the Lurk cybercrime group and to infrastructure and activity surrounding the Angler exploit kit. Russian law enforcement actions in 2016 were widely reported to have disrupted the group after large-scale theft from Russian banks and other organizations.
Technically, Lurk is notable for using digital steganography to conceal encrypted payload locations inside bitmap images, extracting hidden data from image bytes and then decrypting it to obtain download information. Observed variants were delivered through compromised websites that loaded exploit content, including Flash exploitation, after which a DLL-based dropper installed the malware. Lurk has been observed as a two-component design consisting of a dropper and payload, with anti-analysis and anti-security-product checks prior to installation. It can establish persistence on infected systems, communicate with command-and-control infrastructure over HTTP or HTTPS, download additional malware, and inject downloaded payloads into browser processes. Reported execution constraints indicate it was intended to run in the context of common Windows browsers.
Observed secondary payloads included click-fraud malware that generated fraudulent impressions and clicks using remotely supplied templates and spoofed referrers. Separate reporting also places Lurk in the broader ecosystem of banking-focused Russian-speaking cybercrime and ties the group to attacks on core banking systems. Delivery has been associated with exploit-kit-driven web compromise and malvertising-linked Angler activity, making Lurk part of the mid-2010s financially motivated exploit-kit and banking-malware landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Lurk was being propagated through an HTML iFrame on compromised websites that loaded a Flash-based exploit for CVE-2013-5330. If a person visiting one of these websites was running a vulnerable version of Adobe Flash, the exploit dropped a DLL file and executed the Lurk malware. | Lurk is a malware downloader that uses digital steganography... Lurk's primary purpose is to download and execute secondary malware payloads.
2015-01-27 - Angler EK "indexm" exploiting CVE-2015-2551 and firing Java exploits [Payload here is most probably Lurk]
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Qaiser's associates are believed to be the Lurk malware gang, responsible for creating the Lurk banking trojan and the Angler exploit kit.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Lurk is heavily obfuscated and uses several custom algorithms to encrypt strings for its C2 servers, imports, registry keys, and security products searches.
Lurk is a malware downloader that uses digital steganography... hiding secret information within a digital format... embed encrypted URLs into an image file by inconspicuously manipulating individual pixels.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware referenced as part of historical Russian arrests and enforcement patterns.
A downloader malware family mentioned as another example of malware using digital steganography.
A downloader malware family that hides encrypted URLs inside bitmap images using digital steganography, contacts C2 infrastructure, extracts hidden download URLs from images, downloads secondary payloads, and injects them into Internet Explorer. The report says observed payloads at the time were click-fraud malware.
Bank-focused malware used against core banking systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.