LOWZERO

First seen
2021-03-15 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 14:42:11

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:kr country_code:jp

Context

LOWZERO is a sophisticated backdoor often used by state-sponsored threat actors. It primarily targets the government and defense sectors in South Korea and Japan.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Lowzero_Auto (yara-rule)

Reports & references

  • go.recordedfuture.com — Cta 2022 0922 (report)
  • malgamy.github.io — The Approach Of Ta413 For Tibetan Targets (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lowzero (report)

External references