追溯朝鲜APT组织Lazarus的攻击历程
2019-12-02 • Threat Book • Tracing the attack history of the North Korean APT organization Lazarus •
The FreeBuf article profiles Lazarus as a North Korea-linked group also known as APT38 or Guardians of Peace, summarizing activity from early political attacks against the United States and South Korea through later financial, ransomware, cryptocurrency, and infrastructure incidents. It cites examples including Sony Pictures, Bangladesh Bank, WannaCry, cryptocurrency exchange theft, and the Indian Kudankulam nuclear plant case, with tooling references such as DarkSeoul, Destover, Alreay, Worldbit-bot, and Dtrack. The technical focus is on tracking Lazarus by shared code fragments across malware families, using tools such as BinDiff, YARA generation, and VirusTotal content searches. The article highlights a WannaCry code fragment that reportedly correlates with Alreay samples, illustrating how reusable code can support hunting for related Lazarus components.