HOPLIGHT is a Windows malware family associated with North Korean state activity tracked as HIDDEN COBRA and broadly linked to the Lazarus ecosystem. It has been described both as a remote access trojan and as a proxy or tunneling implant because many observed samples primarily relay or disguise command-and-control traffic, while related variants provide broader host-control functionality. Public reporting also links Hoplight-lineage tooling to espionage operations tracked by CrowdStrike as LABYRINTH CHOLLIMA.
HOPLIGHT commonly targets Windows systems and has been observed as 32-bit and 64-bit executables and DLLs. Core capabilities include host reconnaissance, collection of system metadata such as operating system details, storage information, and system time, remote command execution, file upload and download, file and process manipulation, service control, registry modification, and process injection. Some variants also act as connection proxies to obfuscate or reroute operator traffic between compromised hosts and upstream infrastructure.
A defining characteristic of HOPLIGHT is its attempt to make malicious traffic resemble legitimate SSL or TLS communications. Variants have used public SSL certificates, PolarSSL test certificates, fake certificate generation, and pseudo-SSL or fake-TLS handshakes to blend command-and-control traffic with normal encrypted network activity. In some cases, post-handshake traffic is additionally protected with custom encryption rather than the negotiated TLS session key. HOPLIGHT has also used zlib compression to obfuscate communications payloads and has been documented using its command-and-control channel for data exfiltration. Multiple command-and-control channels or fallback paths have been observed, improving resilience if one communication path fails.
Persistence mechanisms vary by sample. Reported methods include Windows service installation, modification of LSASS security package loading, and recompilation or modification of WMI Managed Object Format components to execute commands and maintain access. Some variants have also modified firewall settings to facilitate communications. The malware has been observed hooking or injecting into running processes, including LSASS in certain variants, indicating post-compromise tradecraft oriented toward stealth and durable access.
HOPLIGHT is most strongly associated with Lazarus or HIDDEN COBRA operations and has appeared in U.S. government malware analysis reporting alongside other DPRK-linked implants and support tools. Its blend of proxying, covert communications, persistence, and remote administration makes it suitable for espionage-oriented intrusions and broader post-exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Some of the malware variants in this report, such as CROWDEDFLOUNDER, HOPLIGHT, and ELECTRICFISH were previously reported...
...the espionage-focused entity employing malware with Hoplight lineage.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
These files are then recompiled by invoking wmiprvse.exe through svchost.exe: "C:\Windows\system32\wbem\wmiprvse.exe -Embedding".
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
When executed, the artifact sets up the service, 'Network UDP Trace Management Service'... The service is started by invoking svchost.exe.
Recent malware variants have been observed modifying the MOF files within the system registry to run specific commands and create persistency on the system.
The malware is capable of the following functions: ---Begin Malware Capability--- ... Inject into Running Processes
When executed, the artifact sets up the service, 'Network UDP Trace Management Service'... The service is started by invoking svchost.exe.
This artifact contains the following notable strings: ---Begin Notable Strings--- CompanyName Adobe System Incorporated FileDescription MicrosoftWindows TransFilter/FilterType : 01 WindowsNT Service
The malware is capable of the following functions: ---Begin Malware Capability--- ... Inject into Running Processes
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
After the TLS authentication is completed this particular malware does NOT use the session key that is generated via TLS. It uses a custom Linear Feedback Shift Register (LFSR) encryption scheme to encrypt all communications after the completion of the handshake.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
HOPLIGHT Proxy payload to obfuscate and/or re-route traffic between infected hosts and C2.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
265 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
63 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware lineage associated with LABYRINTH CHOLLIMA espionage operations.
... HOPLIGHT ... (v1.3→v1.4) ...
HOPLIGHT (v1.3→v1.4)
Malware observed injecting into running processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.