Skip to content

BlueNoroff

BlueNoroff is a North Korean state-linked malware and intrusion cluster widely tracked as a financially motivated subgroup of Lazarus.

Profile source: Mallory opens in a new tab

BlueNoroff

Family profile

BlueNoroff is a North Korean state-linked malware and intrusion cluster widely tracked as a financially motivated subgroup of Lazarus. It has been associated with long-running operations against banks, SWIFT-connected environments, financial and trading firms, casinos, and cryptocurrency businesses, and more recently with social-engineering-heavy compromises targeting high-value organizations in the crypto sector. BlueNoroff activity is characterized by tailored multi-stage toolchains rather than a single stable malware family, with operators deploying loaders, backdoors, tunneling utilities, keyloggers, SWIFT-focused modules, and information-stealing components according to the victim environment.

In bank intrusions, BlueNoroff has been linked to compromises of internal infrastructure adjacent to SWIFT systems rather than exploitation of SWIFT itself. Documented tradecraft includes long-term persistence, lateral movement with privileged accounts, remote task scheduling, use of passive backdoors and TCP tunneling, keylogging, interception of transaction-related data, and tampering with SWIFT software components to disable integrity checks and manipulate processing workflows. The operators have also shown strong anti-forensics discipline, including splitting components across hosts, password-protecting payload installation, rolling back modified files, and wiping malware after detecting investigation activity.

Delivery methods have included watering-hole attacks against financial-sector websites that served exploits for known Adobe Flash Player and Microsoft Silverlight vulnerabilities, compromising victims that had not applied available patches. More recent reporting also ties BlueNoroff to highly targeted social engineering using fake business opportunities, deepfakes, and malicious meeting-related software or extensions to gain initial access, particularly in cryptocurrency-focused environments.

BlueNoroff is best understood as an operational subset of Lazarus dedicated to revenue generation and financial theft. Its campaigns demonstrate a blend of espionage-grade intrusion discipline and criminal monetization objectives, with emphasis on stealth, customized tooling, and post-compromise actions designed to reach payment systems, sensitive financial workflows, or valuable credentials and data.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Keylogging
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Process Injection

Observed infrastructure

Last seven days

First activity
Sep 3, 2026
Last activity
Sep 10, 2026
Feed role
Distribution
Host form
0 IP / 5 hostnames

Leading locations

  • US3
  • CA1
  • IN1

Leading providers

  • Cloudflare, Inc.1
  • DFINITY USA Research, LLC1
  • Micro Hosting Private Limited1
  • Namecheap, Inc.1
  • OVH SAS1

Infrastructure traits

  • Hosting 5
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Lazarus

Lazarus under the Hood BlueNoroff HOTWAX REDSHAWL WORMHOLE

DPRK

Huntress wrote in a recent blog post describing the BlueNoroff targeted attack where threat actors tied to the Democratic People's Republic of Korea (DPRK) compromised a victim organization with malicious Zoom extensions and deepfakes.

Exploited software

Vulnerabilities linked to BlueNoroff

4 CVEs

Reporting

Research mentioning BlueNoroff

Jun 23
Darkatlas

Bluenoroff (APT38) Live Infrastructure Hunting - Darkatlas

North Korea-linked Lazarus Group and its financially motivated subgroup Bluenoroff/APT38 have been tied to long-running intrusions against banks, SWIFT-connected environments, cryptocurrency businesses, casinos, and other financial targets worldwide. Reporting from multiple investigations links the actors to operations including the Bangladesh Bank theft, compromises at Bancomext and Banco de Chile, and intrusions at banks in Southeast Asia and Europe. Investigators found that the group maintained access for months, compromised SWIFT Alliance infrastructure, patched SWIFT-related components to suppress integrity checks, harvested transaction data, and used keylogging, lateral movement, and anti-forensic measures to conceal activity and disrupt investigations. Researchers also documented recurring Lazarus tradecraft across these campaigns, including spear phishing, watering-hole attacks, brute force, exploitation of web and client vulnerabilities, fake-TLS command-and-control, service-based persistence, and reuse of malware families and tooling. Technical reporting connected incidents through shared backdoor design, tunneling tools, SWIFT-focused modules, and malware such as SQCSVC and SWPSVC, while newer infrastructure hunting identified phishing domains, linked IP space, and a macOS sample named localfile~.x64 communicating with 104.168.136.24. The combined findings reinforce attribution of these financially driven operations to the Lazarus ecosystem and show an adaptive capability spanning traditional banking networks and digital-asset platforms.

Dec 20
Proofpoint Threat Insight

North Korea Bitten by Bitcoin Bug: Financially motivated campaigns reveal new dimension of the Lazarus Group | Proofpoint US

Aug 23
Us Cert Gov Legacy

HIDDEN COBRA โ€“ North Koreaโ€™s DDoS Botnet Infrastructure

May 13
Baesystemsai Blogspot

BAE Systems Threat Research Blog: Cyber Heist Attribution

Apr 25
Baesystemsai Blogspot

BAE Systems Threat Research Blog: Two bytes to $951m

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.