朝鲜APT双雄联手:Kimsuky 偷情报当 “眼睛”,Lazarus 盗币填 “钱袋”!

2025-11-20 紫队安全研究 North Korean APT Duo Joins Forces: Kimsuky Steals Intelligence as the “Eyes,” Lazarus Steals Crypto to Fill the “Money Bag”

https://mp.weixin.qq.com/s/h4TCYVjdLALg4XfJr1jC0w

Thumbnail for 朝鲜APT双雄联手:Kimsuky 偷情报当 “眼睛”,Lazarus 盗币填 “钱袋”!

The Chinese-language article summarizes claims that Kimsuky and Lazarus operate with complementary roles, with Kimsuky focused on intelligence collection and Lazarus focused on cryptocurrency theft. It describes a reported Korean blockchain-company compromise in which Kimsuky allegedly used an academic-conference lure and HWP or MSC files to deploy FPSpy and KLogEXE, collect credentials and network information, and pass that intelligence to Lazarus. The Lazarus stage is described as using CVE-2024-38193, malicious Node.js project files, InvisibleFerret, Fudmodule, and BeaverTail to gain SYSTEM privileges, evade detection, and steal blockchain wallet keys and transaction data. The article also claims shared C2 infrastructure, cleanup actions, and broader DPRK targeting of military, financial, energy, medical, academic, and critical-infrastructure sectors, but its indicators include placeholders and should be treated cautiously where values are not concrete.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1 2025-11-20 2025-11-20
HASH a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 2025-11-20 2025-11-20

Related Actors

Related Reports

« Back