국내 타깃형 APT공격그룹 - 라자루스(LAZARUS)

2020-03-04 Igloo Domestic targeting APT attack group - LAZARUS

https://www.igloo.co.kr/security-information/%ec%95%8c%ec%95%84%eb%b3%b4%ec%9e%a1-series-%ea%b5%ad%eb%82%b4-%ed%83%80%ea%b9%83%ed%98%95-apt%ea%b3%b5%ea%b2%a9%ea%b7%b8%eb%a3%b9-%eb%9d%bc%ec%9e%90%eb%a3%a8%ec%8a%a4lazarus/

Igloo summarizes Lazarus as a suspected North Korean state-backed group active against domestic Korean targets, with historical links cited to Operation Troy, Sony Pictures, Hidden Cobra, Andariel, and BlueNoroff. The analyzed cases center on malicious Hangul documents disguised as real estate reports, investment or system contracts, company documents, proof-submission requests, and CES participation forms. The infection chains use PostScript or macro content with XOR-encoded shellcode, normal-process injection into explorer.exe, staged downloads from C2 servers, and final payloads including Manuscrypt/Bankshot or DLLs such as WEB_Troy.dll that send victim PC information to attacker infrastructure. The report highlights why Korean organizations should treat convincing HWP lures as a persistent intrusion vector, especially where patched vulnerabilities and quiet information theft make compromise difficult for users to notice.

Related Actors

Related Reports

« Back