CyberSecurityBoardThreat Intel · CVEs · Products

Tag: Lazarus Group

Malware

MISTPEN Downloader: Lightweight Malware Loader

MISTPEN is a lightweight downloader used by Lazarus Group to communicate with C2 servers via Microsoft Graph API and OneDrive. It retrieves…

downloader Lazarus Group Microsoft Graph API MISTPEN
August 12, 2026
Malware

ForestTiger (ScoringMathTea) Backdoor

ForestTiger, also known as ScoringMathTea, is a backdoor used by Lazarus Group to provide remote access to compromised hosts. It is deployed…

backdoor ForestTiger Lazarus Group ScoringMathTea
August 12, 2026
Malware

FudModule Rootkit: Version 3.1 Enhancements

FudModule is a kernel-mode rootkit used by Lazarus Group since at least 2022. Version 3.1 adds the ability to disable Windows Smart…

FudModule Lazarus Group ML-KEM rootkit
August 12, 2026
Cyber Products

SecurityPDF: Trojanized PDF Viewer

SecurityPDF is a trojanized PDF viewer that appears to be a legitimate product but contains malicious code. It is used by Lazarus…

Lazarus Group PDF Viewer SecurityPDF Trojanized
August 12, 2026