Malware · critical

How to fixLAZARUS_BLUENOROFF_APT

Lazarus Group / Bluenoroff APT threat

What this error means

LAZARUS_BLUENOROFF_APT is a critical-severity malware/security problem. Lazarus and its sub-group Bluenoroff are state-sponsored advanced persistent threat (APT) actors. They target global financial institutions, SWIFT networks, cryptocurrency exchanges, and blockchain platforms using sophisticated custom malware, trojanized applications, and spear-phishing. It's also often linked to exploitation of public-facing server vulnerabilities. See the troubleshooting steps below for the fix.

Before you begin

Save open work and back up important files. Note any recent driver or hardware changes. If Windows cannot start, use the startup guide first.

Work through these checks

0 of 4 complete
01Perform network-wide host and memory forensics to locate custom implants

Perform network-wide host and memory forensics to locate custom implants.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
02Enforce application control and code signing integrity policies

Enforce application control and code signing integrity policies.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
03Revoke compromised administrative access and certificates

Revoke compromised administrative access and certificates.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
04Implement strict network segmentation for critical environments

Implement strict network segmentation for critical environments.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help

Possible causes

  • Spear-phishing emails targeting high-value corporate employees
  • Downloading trojanized open-source utilities or crypto wallet apps
  • Exploitation of public-facing server vulnerabilities