NACHOCHEESE

Aliases: Cyruslish, TWOPENCE, VIVACIOUSGIFT

First seen
2019-05-01 00:00:00
Malware type
rat
Profile updated
2026-07-07 14:02:58

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Context

According to FireEye, NACHOCHEESE is a command-line tunneler that accepts delimited C&C IPs or domains via command-line and gives actors shell access to a victim's system.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Nachocheese_Auto (yara-rule)

Reports & references

  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • virusbulletin.com — Vb2018 Kalnai Poslusny (report)
  • ESET — Demystifying Targeted Malware Used Polish Banks (report)
  • Mandiant — Rpt Apt38 2018 (report)
  • raw.githubusercontent.com — Group Ib Lazarus (report)
  • baesystemsai.blogspot.com — Lazarus False Flag Malware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nachocheese (report)
  • CISA — Ar20 239B (report)

External references