ThreatNeedle

MITRE ATT&CK: S0665 View on attack.mitre.org

Aliases: ThreatNeedle

First seen
2019-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:06:07

Targeted industries: financial-services defense-and-aerospace technology-and-telecommunications

Context

ThreatNeedle is a backdoor that has been used by Lazarus Group since at least 2019 to target cryptocurrency, defense, and mobile gaming organizations. It is considered to be an advanced cluster of Lazarus Group's Manuscrypt (a.k.a. NukeSped) malware family.

Detection coverage

  • 357 Sigma rules

Malware & tools used

  • Registry Run Keys / Startup Folder (attack-pattern)
  • Malicious File (attack-pattern)
  • Windows Service (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Information Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Compression (attack-pattern)
  • Data from Local System (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Fileless Storage (attack-pattern)
  • Modify Registry (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)

Used by threat actors

Reports & references

  • Kaspersky — 100803 (report)
  • MITRE ATT&CK — S0665 (report)

External references