SYMBOLCOMMON_NAMEaka. SYNONYMS
win.lpeclient (Back to overview)

LPEClient

aka: LPEClientTea

Actor(s): Lazarus Group

VTCollection    

LPEClient is an HTTP(S) downloader that expects two command line parameters: an encrypted string containing two URLs (a primary and a secondary C&C server), and the path on the victim's file system to store the downloaded payload.

It sends detailed information about the victim's environment, like computer name, type and number of processors, computer manufacturer, product name, major and minor Windows versions, architecture, memory information, installed security software and the version of the ntoskrnl.exe from its version-information resource.

LPEClient uses specific 32-bit values to represent its execution state (0x59863F09 when connecting via the WinHTTP interface, 0xA9348B57 via WinINet), or the nature of HTTP requests to the C&C servers (0xF07D6B34 when sending system information, 0xEF8C0D51 when requesting a DLL payload, 0xCB790A25 when reporting the successful loading of the DLL, 0xD7B20A96 when reporting the state of the the DLL execution). As the final step, malware looks for the export CloseEnv and executes it.

References
2023-10-27 ⋅ Kaspersky ⋅ Seongsu Park
A cascade of compromise: unveiling Lazarus’ new campaign
LPEClient PostNapTea
2023-04-12 ⋅ Kaspersky Labs ⋅ Seongsu Park
Following the Lazarus group by tracking DeathNote campaign
Bankshot BLINDINGCAN ForestTiger LambLoad LPEClient MimiKatz NedDnLoader Racket Downloader Volgmer
2021-10-08 ⋅ Virus Bulletin ⋅ Seongsu Park
Multi-universe of adversary: multiple campaigns of the Lazarus group and their connections
Dacls AppleJeus AppleJeus Bankshot BookCodes RAT Dacls DRATzarus LCPDot LPEClient
2021-10-07 ⋅ Virus Bulletin ⋅ Byeongjae Kim, Dongwook Kim, Taewoo Lee
Operation Bookcodes – targeting South Korea
BookCodes RAT LPEClient
2021-02-25 ⋅ Kaspersky Labs ⋅ Seongsu Park, Vyacheslav Kopeytsev
Lazarus targets defense industry with ThreatNeedle
HTTP(S) uploader LPEClient Volgmer
2020-08-13 ⋅ ClearSky ⋅ ClearSky Research Team
Operation ‘Dream Job’ Widespread North Korean Espionage Campaign
DRATzarus LPEClient NedDnLoader
Yara Rules
[TLP:WHITE] win_lpeclient_auto (20260917 | Detects win.lpeclient.)
rule win_lpeclient_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.lpeclient."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.lpeclient"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488d15a7830000 488bc8 e8???????? 84c0 7513 }
            // n = 5, score = 100
            //   488d15a7830000       | inc                 esp
            //   488bc8               | or                  edx, eax
            //   e8????????           |                     
            //   84c0                 | inc                 ecx
            //   7513                 | movzx               eax, byte ptr [ebx + 4]

        $sequence_1 = { 418bc0 4183e00f 48c1e81c 4133948420a50100 8b453c 4333948460a30100 }
            // n = 6, score = 100
            //   418bc0               | mov                 eax, dword ptr [ebp + 0x50]
            //   4183e00f             | inc                 ebx
            //   48c1e81c             | xor                 edx, dword ptr [esp + eax*4 + 0x1a360]
            //   4133948420a50100     | rol                 edx, 0xb
            //   8b453c               | dec                 eax
            //   4333948460a30100     | shr                 eax, 0x1c

        $sequence_2 = { 4c89642420 4533c9 4533c0 488d55b8 ff5018 85c0 }
            // n = 6, score = 100
            //   4c89642420           | inc                 ecx
            //   4533c9               | xor                 cl, al
            //   4533c0               | mov                 byte ptr [edx], cl
            //   488d55b8             | inc                 ecx
            //   ff5018               | add                 ecx, 0xb
            //   85c0                 | inc                 ecx

        $sequence_3 = { 418d0c01 448bc1 48c1e918 83e10f 418bc0 418b948ce0a40100 48c1e814 }
            // n = 7, score = 100
            //   418d0c01             | mov                 eax, eax
            //   448bc1               | dec                 eax
            //   48c1e918             | shr                 eax, 0x1c
            //   83e10f               | inc                 ecx
            //   418bc0               | xor                 edx, dword ptr [esp + eax*4 + 0x1a520]
            //   418b948ce0a40100     | dec                 eax
            //   48c1e814             | shr                 eax, 4

        $sequence_4 = { b940000000 48899c2418030000 ff15???????? 488d4dd0 }
            // n = 4, score = 100
            //   b940000000           | mov                 eax, 1
            //   48899c2418030000     | dec                 eax
            //   ff15????????         |                     
            //   488d4dd0             | mov                 ecx, dword ptr [ebp + 0x750]

        $sequence_5 = { 90 488b4c2458 4885c9 7407 488b11 ff5210 }
            // n = 6, score = 100
            //   90                   | inc                 esp
            //   488b4c2458           | mov                 eax, ecx
            //   4885c9               | dec                 eax
            //   7407                 | shr                 ecx, 0x18
            //   488b11               | and                 ecx, 0xf
            //   ff5210               | inc                 esp

        $sequence_6 = { 4183e00f 48c1e81c 33948120a50100 418b442468 4233948160a30100 c1c20b }
            // n = 6, score = 100
            //   4183e00f             | dec                 eax
            //   48c1e81c             | sub                 esp, eax
            //   33948120a50100       | dec                 eax
            //   418b442468           | lea                 ebp, [esp - 0xad8]
            //   4233948160a30100     | dec                 eax
            //   c1c20b               | sub                 esp, 0xbd8

        $sequence_7 = { b204 488bcf e8???????? 4c8d442420 }
            // n = 4, score = 100
            //   b204                 | lea                 ebp, [esp - 0x30]
            //   488bcf               | dec                 eax
            //   e8????????           |                     
            //   4c8d442420           | sub                 esp, 0x130

        $sequence_8 = { 4863c1 420fb60420 8844343f 483bf3 7ccc }
            // n = 5, score = 100
            //   4863c1               | dec                 eax
            //   420fb60420           | lea                 ecx, [0x1b1c0]
            //   8844343f             | dec                 eax
            //   483bf3               | mov                 dword ptr [esp + 0x20], eax
            //   7ccc                 | inc                 esp

        $sequence_9 = { 85f6 0f88a9060000 418d4424e0 3c58 7712 490fbec4 420fbe8c0860390100 }
            // n = 7, score = 100
            //   85f6                 | dec                 eax
            //   0f88a9060000         | lea                 edx, [0xffffcc2e]
            //   418d4424e0           | lea                 ecx, [ebx + eax]
            //   3c58                 | inc                 esp
            //   7712                 | mov                 eax, ecx
            //   490fbec4             | dec                 eax
            //   420fbe8c0860390100     | shr    ecx, 0x18

    condition:
        7 of them and filesize < 289792
}
Download all Yara Rules