He is everywhere
First seen: 2016-02 •
Last seen: 2026-06
#MagicLine4NX • 2023-03
Lazarus abused DreamSecurity MagicLine4NX and related South Korean security-software distribution paths for watering-hole and supply-chain access against domestic targets in media, technology, defense, chemical, and other sectors. Reporting described exploitation of vulnerable MagicLine4NX components to inject into svchost.exe and execute malware, earlier VeraPort-based delivery of camouflaged signed installers, BYOVD anti-security activity, and Operation GoldGoblin use of compromised media sites and security-software vulnerabilities.
13
Related Reports
1
Affected Countries
39
Months Since
He is everywhere