
A 21-Kilobyte Worm Stalls the Sandbox, Then Mails Itself Onward
A record attributed to 'Lazarus Group' turns out to rest on a single verified artifact: a 2019-vintage MyDoom worm that checks for debuggers, stalls execution, and re-mails itself via SMTP while disguised as lsass.exe. The other 40 hashes, seven IPs, and eight domains attached to the record carry no comparable telemetry.
The only indicator in this record with real telemetry behind it is a 21-kilobyte Windows executable that arrives as an email attachment, checks whether a debugger is watching it, deliberately stalls before doing anything, and then re-mails itself to the next victim. Everything else attached to this record — 40 other file hashes, seven IPs, eight domains, all filed under a "Lazarus Group" actor tag — carries no meaningful telemetry at all.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read