APTMembers
APT

Nine-Megabyte SFX Archive Bundles Five Crimeware Families Under Lazarus Label

A file set attributed to Lazarus Group turns out to be dominated by commodity infostealers and loaders — RedlineStealer, Socelars, Fabookie, Azorult, and SmokeLoader — delivered through a single self-extracting 7-Zip archive. Seven co-firing YARA rules and shared temp-path conventions suggest the archive functions as shared delivery scaffolding rather than a fingerprint of one malware family.

Jul 29, 2026, 13:35 (UTC+9)Last seenJul 29, 2026Severity100ByCTX TeamActorLazarus GroupHastati GroupIOC41MITRE8RegionsBR

A 9.8MB self-extracting 7-Zip archive named 7zS.sfx.exe sits at the center of a file set nominally filed under the Lazarus Group label — but the malware riding inside it has nothing to do with bespoke espionage tooling. The archive, submitted alongside a matching overlay-carrying binary called setup_install.exe on 2022-06-05, carries seven named YARA hits, including Windows_API_Function, INDICATOR_EXE_Packed_ASPack, MALWARE_Win_DLInjector03, INDICATOR_EXE_Packed_VMProtect, AutoIT_Compiled, and…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence