LPEClient is a Lazarus Group malware family used as a loader and information-stealer for victim profiling and payload delivery. Reporting ties it to Lazarus campaigns including DeathNote/Operation DreamJob and later South Korea-focused activity such as Operation SyncHole. It has been observed in intrusion chains initiated through recruiter-themed social engineering, including fake job or skills-assessment lures that delivered trojanized VNC software, as well as in watering-hole and software-exploitation-driven compromises in South Korea.
In the DreamJob/DeathNote activity, a trojanized VNC client triggered creation of LPEClient after execution by the victim. A new LPEClient variant was fetched by MISTPEN from command-and-control infrastructure, alongside RollMid, and CookieTime was executed after LPEClient installation on at least one host. Lazarus also used CookieTime to download additional malware strains including LPEClient, Charamel Loader, ServiceChanger, and CookiePlus during lateral movement. In Operation SyncHole, LPEClient was loaded by a ThreatNeedle variant and was specifically described as being used for victim profiling and payload delivery (T1105).
The malware is associated with Lazarus operations targeting high-value sectors, including defense, aerospace, software vendors, nuclear-related organizations, nuclear engineers, and multiple South Korean industries such as software, IT, financial, semiconductor manufacturing, and telecommunications. Supporting reporting also notes Lazarus use of SIGNBT and LPEClient in repeated compromises of a software vendor during a broader March-August 2023 campaign.
Infrastructure associated with campaigns using LPEClient included compromised WordPress web servers running PHP-based services as command-and-control in the DreamJob/DeathNote activity. High-confidence related malware and tooling mentioned alongside LPEClient include ThreatNeedle, MISTPEN, RollMid, CookieTime, CookiePlus, Charamel Loader, ServiceChanger, SIGNBT, COPPERHEDGE, Ranid Downloader, and wAgent.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The second was identified as a new LPEClient variant. ... CookieTime was used to download several malware strains, including LPEClient, Charamel Loader, ServiceChanger, and an updated version of CookiePlus...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-compromise tool used for victim profiling and payload delivery; in this operation it is loaded by ThreatNeedle (not by SIGNBT) to deliver additional payloads.
Lazarus-linked info-stealer/loader with advanced evasion (e.g., disabling user-mode syscall hooking, restoring system library memory sections) and early-stage injection to load additional malware.
Additional Lazarus-associated payload created/installed after execution of a trojanized VNC client.
A Lazarus payload/variant fetched by MISTPEN and later also downloaded by CookieTime during lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.