FILEMembers
FILE

A 21-Kilobyte Worm Stalls the Sandbox, Then Mails Itself Onward

A record attributed to 'Lazarus Group' turns out to rest on a single verified artifact: a 2019-vintage MyDoom worm that checks for debuggers, stalls execution, and re-mails itself via SMTP while disguised as lsass.exe. The other 40 hashes, seven IPs, and eight domains attached to the record carry no comparable telemetry.

Sep 23, 2026, 14:55 (UTC+9)Last seenSep 23, 2026Severity72ByCTX TeamActorLazarus GroupHastati GroupIOC56RegionsCHCNJOUS

The only indicator in this record with real telemetry behind it is a 21-kilobyte Windows executable that arrives as an email attachment, checks whether a debugger is watching it, deliberately stalls before doing anything, and then re-mails itself to the next victim. Everything else attached to this record — 40 other file hashes, seven IPs, eight domains, all filed under a "Lazarus Group" actor tag — carries no meaningful telemetry at all.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence