Heloag
- First seen
- 2021-09-01 00:00:00
- Malware type
- downloader, rat
- Profile updated
- 2026-07-07 15:05:10
Targeted industries: government-and-public-sector
Targeted regions: country_code:kr
Context
Heloag is a sophisticated malware commonly associated with APT37 and the Lazarus Group, known for targeting the government sector. It primarily functions as a downloader and remote access tool, facilitating cyber espionage operations against South Korea.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Heloag_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Heloag (report)
- Kaspersky — 29693 (report)