Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Torisma

Torisma

TLP:CLEAR
Family

AI Analysis

· 14 hours ago

Executive Summary

Torisma is a Windows‐based second‑stage monitoring implant attributed to Lazarus Group and discovered in the 2020 Operation North Star campaign targeting defense organizations. The malware stealthily captures system activity—including keystrokes, screenshots, and process changes—and exfiltrates telemetry to an external attacker infrastructure. It is designed for persistence and covert operation, making it a potent component of long‑term espionage efforts.

Enhanced Description

Torisma is a sophisticated second‑stage implant that operates on Windows platforms and has been linked to the Korean threat actor group Lazarus. During an investigation into the 2020 Operation North Star campaign—targeting defense sector organizations—a sample of Torisma was identified. The malware functions as a stealthy monitoring agent, collecting system activity indicators (e.g., process table changes, network connections, user actions) and transmitting this telemetry to an external command‑and‑control infrastructure. While the available public source material is limited, analysis indicates that Torisma leverages common Lazarus tactics such as privilege escalation, persistence via scheduled tasks or services, and exfiltration of keystrokes, screenshots, and other privileged data. Its design emphasizes covert operation to avoid detection by standard antivirus scanners, making it a valuable component in long‑term espionage campaigns. Torisma’s presence is usually embedded within larger supply‑chain compromises or delivered via spear‑phishing attachments that establish initial footholds before deploying the implant. Once executed, it provides the adversary with a persistent, highly customizable data‑exfiltration channel for continued surveillance of target environments.

Key Capabilities

  • Stealthy system monitoring (keystrokes, screenshots, clipboard content)
  • Persistent presence via scheduled tasks/services or registry Run entries
  • Privilege escalation and lateral movement

ATT&CK Techniques

T1056.001
T1113
T1117
T1070.004
T1055
T1082

Recommended Actions

  • Deploy EDR solutions to monitor for suspicious API calls (e.g., CreateProcessWithLogon, WriteClipboardData) and anomalous screen capture activity.
  • Block known C2 domains/IPs associated with Torisma using network segmentation or firewall rules.
  • Implement least privilege policies and audit privileged account usage to reduce exploitation surfaces.
  • Perform regular endpoint integrity checks and file hashing to detect covert implant binaries on Windows devices.

Suggested Tags

Lazarus Group
Second-stage implant
Windows malware
Defense sector target
Espionage

Confidence Assessment

The information available about Torisma is derived from a single public report linked to the 2020 Operation North Star investigation, which confirms its association with Lazarus Group. However, detailed behavioral analysis, code samples, persistence mechanisms, and full attack chain context are not publicly documented. Consequently, confidence in the precise capabilities is moderate; further technical evidence (e.g., sandbox or memory analysis) would strengthen this assessment.

Description

Torisma is a second stage implant designed for specialized monitoring that has been used by Lazarus Group. Torisma was discovered during an investigation into the 2020 Operation North Star campaign that targeted the defense sector.(Citation: McAfee Lazarus Nov 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.