딥시크(DeepSeek) 피싱 사이트를 통해 유포되는 라자루스(Lazarus) 악성코드 분석 보고서

2025-02-27 Nurilab Cyber threat report on Phishing, Lazarus

https://blog.naver.com/nurilab1/223759032693

Thumbnail for 딥시크(DeepSeek) 피싱 사이트를 통해 유포되는 라자루스(Lazarus) 악성코드 분석 보고서

Nurilab describes phishing sites impersonating DeepSeek and abusing the brand's popularity to lure users into a fake partnership registration flow. The site presents a Captcha-like process that instructs users to press Windows+R, paste clipboard content, and run a PowerShell command, matching ClickFix-style social engineering. The excerpt attributes the malware delivery activity to Lazarus and notes that many DeepSeek-themed impersonation domains are being observed through AskURL and AskBRAND telemetry.

Related Actors

Related Reports

« Back