딥시크(DeepSeek) 피싱 사이트를 통해 유포되는 라자루스(Lazarus) 악성코드 분석 보고서
2025-02-27 • Nurilab • Cyber threat report on Phishing, Lazarus •
Nurilab describes phishing sites impersonating DeepSeek and abusing the brand's popularity to lure users into a fake partnership registration flow. The site presents a Captcha-like process that instructs users to press Windows+R, paste clipboard content, and run a PowerShell command, matching ClickFix-style social engineering. The excerpt attributes the malware delivery activity to Lazarus and notes that many DeepSeek-themed impersonation domains are being observed through AskURL and AskBRAND telemetry.
Related Actors
Related Reports
Shares tag: Lazarus • Same author: Nurilab • Published within a month
Shares tag: Lazarus • Same author: Nurilab • Published within a month
Shares tag: Lazarus • Same author: Nurilab • Published within a month
2025-03-25 •
60% Match
Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup
JPCERT
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month