ThreatNeedle — Malware Profile

ThreatNeedle is a backdoor that has been used by Lazarus Group since at least 2019 to target cryptocurrency, defense, and mobile gaming organizations. It is considered to be an advanced cluster of Lazarus Group's Manuscrypt (a.k.a. NukeSped) malware family.

MITRE ATT&CK techniques (14)

IntelFusions coverage

Attributed threat actors

Read the full analysis on IntelFusions