HazyLoad is a custom proxy tool associated with North Korean threat activity, particularly operations linked to the Lazarus umbrella and the Andariel/Onyx Sleet cluster. It has been observed as post-exploitation tooling rather than as a primary initial-access payload, indicating a role in maintaining attacker connectivity and enabling follow-on operations after compromise. Reporting places it in enterprise intrusions involving opportunistic exploitation of exposed infrastructure as well as in a late-2023 cryptocurrency-focused supply-chain intrusion.
In Operation Blacksmith, HazyLoad appeared alongside DLang-based malware families including BottomLoader, which was used to fetch additional payloads, and other Lazarus-linked tooling. Its use in that campaign overlapped with tradecraft attributed to Andariel, a subgroup commonly associated with initial access, reconnaissance, and establishment of long-term espionage access. HazyLoad was also identified as a common artifact in intrusions against organizations in sectors including manufacturing, agriculture, and physical security.
Separate reporting ties HazyLoad to a cryptocurrency exchange intrusion in which attackers compromised a software update mechanism, deployed a trojanized installer and a Golang RAT, then introduced HazyLoad during post-exploitation. In that case, the broader intrusion included remote-access enablement and account manipulation, consistent with HazyLoad supporting covert internal connectivity or traffic relaying within an established foothold.
The available evidence supports classifying HazyLoad as proxy-oriented post-compromise malware used to facilitate persistence and operational access. It is associated with Windows-centric intrusion chains and with DPRK-linked actors engaged in espionage and financially motivated operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post-exploitation process: Installed preliminary tools Custom Proxy tool named HazyLoad
"Tools Rifle, ActiveX 0-day, Valefor, HazyLoad, HotCriossant, DTrack, UnitBot"
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom proxy tool used during post-exploitation to support access and pivoting in the cryptocurrency-targeting intrusion.
Custom proxy/reverse-proxy tool used to maintain direct access and provide redundant backdoor connectivity after initial compromise, reducing the need to repeatedly exploit the initial-access vulnerability.
Referenced as malware associated with exploitation of JetBrains TeamCity CVE-2023-42793 (no further details provided in the content).
Tooling attributed to NICKEL HYATT; the content lists it as part of the group’s toolset but does not describe functionality beyond being a named tool.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.