
Nine-Megabyte SFX Archive Bundles Five Crimeware Families Under Lazarus Label
A file set attributed to Lazarus Group turns out to be dominated by commodity infostealers and loaders — RedlineStealer, Socelars, Fabookie, Azorult, and SmokeLoader — delivered through a single self-extracting 7-Zip archive. Seven co-firing YARA rules and shared temp-path conventions suggest the archive functions as shared delivery scaffolding rather than a fingerprint of one malware family.
A 9.8MB self-extracting 7-Zip archive named 7zS.sfx.exe sits at the center of a file set nominally filed under the Lazarus Group label — but the malware riding inside it has nothing to do with bespoke espionage tooling. The archive, submitted alongside a matching overlay-carrying binary called setup_install.exe on 2022-06-05, carries seven named YARA hits, including Windows_API_Function, INDICATOR_EXE_Packed_ASPack, MALWARE_Win_DLInjector03, INDICATOR_EXE_Packed_VMProtect, AutoIT_Compiled, and…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read