ThreatNeedle
MITRE ATT&CK: S0665 View on attack.mitre.org
Aliases: ThreatNeedle
- First seen
- 2019-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:06:07
Targeted industries: financial-services defense-and-aerospace technology-and-telecommunications
Context
ThreatNeedle is a backdoor that has been used by Lazarus Group since at least 2019 to target cryptocurrency, defense, and mobile gaming organizations. It is considered to be an advanced cluster of Lazarus Group's Manuscrypt (a.k.a. NukeSped) malware family.
Detection coverage
- 357 Sigma rules
Malware & tools used
- Registry Run Keys / Startup Folder (attack-pattern)
- Malicious File (attack-pattern)
- Windows Service (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Information Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Compression (attack-pattern)
- Data from Local System (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Fileless Storage (attack-pattern)
- Modify Registry (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
Used by threat actors
- Lazarus Group (threat-actor)
Reports & references
- Kaspersky — 100803 (report)
- MITRE ATT&CK — S0665 (report)