국내·외 리서쳐 공격에 사용된 북한 라자루스 그룹의 최신 제로데이 취약점 및 관련 악성코드 분석
2021-03-11 • S2W • Analysis of the latest zero-day vulnerabilities and related malware of the North Korean Lazarus Group used in attacks on domestic and foreign researchers •
Attachments
K-8.pdf (3 MB)
ENKI and S2W describe Lazarus operations against domestic and foreign security researchers that used social media contact and zero-day browser exploit delivery. The actors posed as vulnerability researchers on Twitter, LinkedIn, Telegram, Discord, and related channels, then sent tailored Visual Studio projects, MHT technical documents, or links to attacker-controlled exploit blogs. The report highlights IE and Chrome zero-day use, ThreatNeedle malware, registry based encrypted configuration, and targeting of offensive security researchers and Korean security firms before the public Google and Microsoft disclosures.