BlueNoroff is a North Korean state-linked malware and intrusion cluster widely tracked as a financially motivated subgroup of Lazarus. It has been associated with long-running operations against banks, SWIFT-connected environments, financial and trading firms, casinos, and cryptocurrency businesses, and more recently with social-engineering-heavy compromises targeting high-value organizations in the crypto sector. BlueNoroff activity is characterized by tailored multi-stage toolchains rather than a single stable malware family, with operators deploying loaders, backdoors, tunneling utilities, keyloggers, SWIFT-focused modules, and information-stealing components according to the victim environment.
In bank intrusions, BlueNoroff has been linked to compromises of internal infrastructure adjacent to SWIFT systems rather than exploitation of SWIFT itself. Documented tradecraft includes long-term persistence, lateral movement with privileged accounts, remote task scheduling, use of passive backdoors and TCP tunneling, keylogging, interception of transaction-related data, and tampering with SWIFT software components to disable integrity checks and manipulate processing workflows. The operators have also shown strong anti-forensics discipline, including splitting components across hosts, password-protecting payload installation, rolling back modified files, and wiping malware after detecting investigation activity.
Delivery methods have included watering-hole attacks against financial-sector websites that served exploits for known Adobe Flash Player and Microsoft Silverlight vulnerabilities, compromising victims that had not applied available patches. More recent reporting also ties BlueNoroff to highly targeted social engineering using fake business opportunities, deepfakes, and malicious meeting-related software or extensions to gain initial access, particularly in cryptocurrency-focused environments.
BlueNoroff is best understood as an operational subset of Lazarus dedicated to revenue generation and financial theft. Its campaigns demonstrate a blend of espionage-grade intrusion discipline and criminal monetization objectives, with emphasis on stealth, customized tooling, and post-compromise actions designed to reach payment systems, sensitive financial workflows, or valuable credentials and data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Considering that Lazarus Group is still active in various cyberespionage and cybersabotage activities, we have segregated its subdivision focusing on attacks on banks and financial manipulations into a separate group which we call Bluenoroff (after one of the tools they used).
Considering that Lazarus Group is still active in various cyberespionage and cybersabotage activities, we have segregated its subdivision focusing on attacks on banks and financial manipulations into a separate group which we call Bluenoroff (after one of the tools they used).
Considering that Lazarus Group is still active in various cyberespionage and cybersabotage activities, we have segregated its subdivision focusing on attacks on banks and financial manipulations into a separate group which we call Bluenoroff (after one of the tools they used).
Considering that Lazarus Group is still active in various cyberespionage and cybersabotage activities, we have segregated its subdivision focusing on attacks on banks and financial manipulations into a separate group which we call Bluenoroff (after one of the tools they used).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus under the Hood BlueNoroff HOTWAX REDSHAWL WORMHOLE
Huntress wrote in a recent blog post describing the BlueNoroff targeted attack where threat actors tied to the Democratic People's Republic of Korea (DPRK) compromised a victim organization with malicious Zoom extensions and deepfakes.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BlueNoroff is an APT group known for targeting cryptocurrency organizations through sophisticated malware and social engineering campaigns.
A DPRK-attributed macOS-focused intrusion set/campaign described as using social engineering (including deepfakes) and malicious Zoom extensions to compromise victims, then deploying backdoor malware and information stealers; also noted as evolving tooling (including novel loaders) to blend into macOS environments and target high-value sectors like Web3/crypto.
Referenced as part of a multi-stage campaign pattern where only a small number of final-stage stealer payloads are used to extract information, especially in cryptocurrency-focused attacks.
Named Lazarus-linked malware/tooling family discussed in technical reporting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.