BlueNoroff
- First seen
- 2017-02-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Last IoC activity
- 2026-06-15 10:45:04
- Profile updated
- 2026-07-07 14:50:00
Targeted industries: financial-services government-and-public-sector
Targeted regions: country_code:kp country_code:vn country_code:bd country_code:ph
Context
This family contains the BlueNoroff toolkit used for SWIFT manipulation, as used by the Lazarus activity cluster also referred to as BlueNoroff.
Detection coverage
- 2 YARA rules
Used by threat actors
- 2025 Bluenoroff Cryptocurrency Foundation Targeting (campaign)
Detection rules
- SEKOIA_Downloader_Win_Curl_Agent (yara-rule)
- MALPEDIA_Win_Bluenoroff_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Bluenoroff (report)
- media.kasperskycontenthub.com — Lazarus Under The Hood Pdf Final (report)