朝鲜APT双雄联手:Kimsuky 偷情报当 “眼睛”,Lazarus 盗币填 “钱袋”!
2025-11-20 • 紫队安全研究 • North Korean APT Duo Joins Forces: Kimsuky Steals Intelligence as the “Eyes,” Lazarus Steals Crypto to Fill the “Money Bag” •
The Chinese-language article summarizes claims that Kimsuky and Lazarus operate with complementary roles, with Kimsuky focused on intelligence collection and Lazarus focused on cryptocurrency theft. It describes a reported Korean blockchain-company compromise in which Kimsuky allegedly used an academic-conference lure and HWP or MSC files to deploy FPSpy and KLogEXE, collect credentials and network information, and pass that intelligence to Lazarus. The Lazarus stage is described as using CVE-2024-38193, malicious Node.js project files, InvisibleFerret, Fudmodule, and BeaverTail to gain SYSTEM privileges, evade detection, and steal blockchain wallet keys and transaction data. The article also claims shared C2 infrastructure, cleanup actions, and broader DPRK targeting of military, financial, energy, medical, academic, and critical-infrastructure sectors, but its indicators include placeholders and should be treated cautiously where values are not concrete.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1 | 2025-11-20 | 2025-11-20 |
| HASH | a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 | 2025-11-20 | 2025-11-20 |