Lizar
MITRE ATT&CK: S0681 View on attack.mitre.org
Aliases: Tirion, Icebot, DiceLoader, Lizar
- First seen
- 2021-02-01 00:00:00
- Malware type
- rat, loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-08-18 21:59:25
- Profile updated
- 2026-07-07 13:21:53
Targeted industries: financial-services retail-and-hospitality
Context
Lizar is a modular remote access tool written using the .NET Framework that shares structural similarities to Carbanak. It has likely been used by FIN7 since at least February 2021.
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to Lizar (S0681). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 814ac8e93b88c3b3bed80e34598a799616f1ba4338deeda4971728f703bc07fa.bin | 2026-09-02 | 1 |
| file sample | 1c441d7d8abb43824a77a15c539e46eafb8f098c5e0efcc57f8b688a12af18dd.bin | 2026-08-18 | 2 |
| file sample | out.dll | 2026-08-11 | 1 |
Detection coverage
- 2 YARA rules
- 630 Sigma rules
Malware & tools used
- Process Injection (attack-pattern)
- Windows Command Shell (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Python (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Native API (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- LSASS Memory (attack-pattern)
- Windows Credential Manager (attack-pattern)
- Screen Capture (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- PowerShell (attack-pattern)
- Portable Executable Injection (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Email Account (attack-pattern)
- System Information Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Encrypted Channel (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Tool (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Process Discovery (attack-pattern)
Used by threat actors
- FIN7 (threat-actor)
- April 2024 FIN7 Malvertising Campaign (campaign)
- PaperCut Vulnerability Exploitation (campaign)
Detection rules
- SEKOIA_Icebot_Exported_Function (yara-rule)
- MALPEDIA_Win_Diceloader_Auto (yara-rule)
Reports & references
- bi-zone.medium.com — From Pentest To Apt Attack Cybercriminal Group Fin7 Disguises Its Malware As An Ethical Hackers C23C9A75E319 (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- Mandiant — Evolution Of Fin7 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Diceloader (report)
- MITRE ATT&CK — S0681 (report)
- geminiadvisory.io — Fin7 Ransomware Bastion Secure (report)
- threatpost.com — 166194 (report)
- sentinelone.com — Fin7 Reboot Cybercrime Gang Enhances Ops With New Edr Bypasses And Automated Attacks (report)