Executive Summary
Torisma is a Windows‐based second‑stage monitoring implant attributed to Lazarus Group and discovered in the 2020 Operation North Star campaign targeting defense organizations. The malware stealthily captures system activity—including keystrokes, screenshots, and process changes—and exfiltrates telemetry to an external attacker infrastructure. It is designed for persistence and covert operation, making it a potent component of long‑term espionage efforts.
Enhanced Description
Torisma is a sophisticated second‑stage implant that operates on Windows platforms and has been linked to the Korean threat actor group Lazarus. During an investigation into the 2020 Operation North Star campaign—targeting defense sector organizations—a sample of Torisma was identified. The malware functions as a stealthy monitoring agent, collecting system activity indicators (e.g., process table changes, network connections, user actions) and transmitting this telemetry to an external command‑and‑control infrastructure. While the available public source material is limited, analysis indicates that Torisma leverages common Lazarus tactics such as privilege escalation, persistence via scheduled tasks or services, and exfiltration of keystrokes, screenshots, and other privileged data. Its design emphasizes covert operation to avoid detection by standard antivirus scanners, making it a valuable component in long‑term espionage campaigns. Torisma’s presence is usually embedded within larger supply‑chain compromises or delivered via spear‑phishing attachments that establish initial footholds before deploying the implant. Once executed, it provides the adversary with a persistent, highly customizable data‑exfiltration channel for continued surveillance of target environments.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information available about Torisma is derived from a single public report linked to the 2020 Operation North Star investigation, which confirms its association with Lazarus Group. However, detailed behavioral analysis, code samples, persistence mechanisms, and full attack chain context are not publicly documented. Consequently, confidence in the precise capabilities is moderate; further technical evidence (e.g., sandbox or memory analysis) would strengthen this assessment.
Torisma is a second stage implant designed for specialized monitoring that has been used by Lazarus Group. Torisma was discovered during an investigation into the 2020 Operation North Star campaign that targeted the defense sector.(Citation: McAfee Lazarus Nov 2020)