HARDRAIN (Windows)

First seen
2018-01-12 00:00:00
Malware type
backdoor, trojan
Profile updated
2026-07-07 14:03:01

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:us country_code:kr

Context

HARDRAIN is a Windows-based malware associated with North Korean threat actors, particularly the Lazarus Group. It primarily functions as a backdoor, allowing remote access and control over infected systems, and has been used in targeted attacks against the government and energy sectors.

Reports & references

  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • us-cert.gov — Mar 10135536 F (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Hardrain (report)

External references