LazarLoader

First seen
2021-05-15 00:00:00
Malware type
loader
Last IoC activity
2026-05-24 02:01:46
Profile updated
2026-07-07 14:55:44

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:cn

Context

LazarLoader is a malicious loader used by threat actors to download and execute additional payloads on compromised systems. It is known for targeting financial, government, telecommunications sectors in various countries.

Detection coverage

  • 2 YARA rules

Detection rules

  • MALPEDIA_Win_Lazarloader_Auto (yara-rule)
  • SEKOIA_Backdoor_Win_Rollsling (yara-rule)

Reports & references

  • Kaspersky — 108383 (report)
  • asec.ahnlab.com — 53832 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lazarloader (report)

External references