Netskope Threat Labs

Yamabot

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Yamabot is a remote access trojan used by the Lazarus group, documented by JPCERT in 2022 and by Cisco Talos alongside two other Lazarus remote access tools. Its use fits the group's state sponsored operations.

First seen
February 2023
Last seen
October 2026
YamaBot
Alert Name
Generic.YamaBot.A.30E86C06
Generic.YamaBot.A.386EEB30
Generic.YamaBot.A.8E1F6E82
Linux.Backdoor.YamaBot
Win64.Backdoor.Yamabot
Win64.Trojan.Yamabot
Win64.Trojan.YamaBot