BlueNoroff

First seen
2017-02-01 00:00:00
Malware type
trojan
Family
Malware family
Last IoC activity
2026-06-15 10:45:04
Profile updated
2026-07-07 14:50:00

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:kp country_code:vn country_code:bd country_code:ph

Context

This family contains the BlueNoroff toolkit used for SWIFT manipulation, as used by the Lazarus activity cluster also referred to as BlueNoroff.

Detection coverage

  • 2 YARA rules

Used by threat actors

  • 2025 Bluenoroff Cryptocurrency Foundation Targeting (campaign)

Detection rules

  • SEKOIA_Downloader_Win_Curl_Agent (yara-rule)
  • MALPEDIA_Win_Bluenoroff_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Bluenoroff (report)
  • media.kasperskycontenthub.com — Lazarus Under The Hood Pdf Final (report)

External references