NukeSped
- First seen
- 2018-02-01 00:00:00
- Malware type
- trojan, downloader, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 15:41:58
Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities
Targeted regions: country_code:kr country_code:us country_code:jp
Context
This threat can install other malware on your PC, including Trojan:Win32/NukeSped.B!dha and Trojan:Win32/NukeSped.C!dha. It can show you a warning message that says your files will be made publically available if you don't follow the malicious hacker's commands.
Detection coverage
- 5 YARA rules
Detection rules
- ARKBIRD_SOLG_APT_MAL_NK_Lazarus_Nukesped_June_2020_1 (yara-rule)
- ARKBIRD_SOLG_APT_Lazarus_Jun_2021_1 (yara-rule)
- SEKOIA_Backdoor_Win_Volgmer (yara-rule)
- SEKOIA_Backdoor_Win_Nukesped_Andariel (yara-rule)
- ESET_Richheaders_Lazarus_Nukesped_Iconicpayloads_3CX_Q12023 (yara-rule)
Reports & references
- sophos.com — Troj~Nukesped Z (report)
- Microsoft — Malware Encyclopedia Description (report)
- Microsoft — Malware Encyclopedia Description (report)
- Microsoft — Malware Encyclopedia Description (report)
- malwarefixes.com — Win32Nukesped (report)
- alienvault.com — Alienvault Labs Threat Intelligence Update For Usm Anywhere March 25 March 31 2018 (report)