Netskope Threat Labs

GraceWire

ATP Sandbox Adv. HeuristicsAV

GraceWire is a remote access trojan associated with the Lazarus threat group that gives operators backdoor control of infected systems. It has appeared in supply chain style campaigns in which trojanized applications and installers delivered the implant to unsuspecting users, and it supports command execution, file theft, and payload downloads. The family's use in espionage and financially motivated operations reflects Lazarus's blend of intelligence collection and revenue generation.

First seen
February 2022
Last seen
October 2026
Alert Name
Document-Excel.Dropper.GraceWire
Document-Excel.Trojan.GraceWire
Document-Office.Trojan.GraceWire
Document-Word.Dropper.GraceWire
Document-Word.Trojan.GraceWire
GT:VB.GraceWire.1.0268C95A
GT:VB.GraceWire.1.06CC7064
GT:VB.GraceWire.1.22D5FCE2
GT:VB.GraceWire.1.22D5FCE2:B3DCC
GT:VB.GraceWire.1.3056EDAE