NukeSped

First seen
2018-02-01 00:00:00
Malware type
trojan, downloader, spyware
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 15:41:58

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:kr country_code:us country_code:jp

Context

This threat can install other malware on your PC, including Trojan:Win32/NukeSped.B!dha and Trojan:Win32/NukeSped.C!dha. It can show you a warning message that says your files will be made publically available if you don't follow the malicious hacker's commands.

Detection coverage

  • 5 YARA rules

Detection rules

  • ARKBIRD_SOLG_APT_MAL_NK_Lazarus_Nukesped_June_2020_1 (yara-rule)
  • ARKBIRD_SOLG_APT_Lazarus_Jun_2021_1 (yara-rule)
  • SEKOIA_Backdoor_Win_Volgmer (yara-rule)
  • SEKOIA_Backdoor_Win_Nukesped_Andariel (yara-rule)
  • ESET_Richheaders_Lazarus_Nukesped_Iconicpayloads_3CX_Q12023 (yara-rule)

Reports & references

  • sophos.com — Troj~Nukesped Z (report)
  • Microsoft — Malware Encyclopedia Description (report)
  • Microsoft — Malware Encyclopedia Description (report)
  • Microsoft — Malware Encyclopedia Description (report)
  • malwarefixes.com — Win32Nukesped (report)
  • alienvault.com — Alienvault Labs Threat Intelligence Update For Usm Anywhere March 25 March 31 2018 (report)

External references