최근 Lazarus그룹의 공격방식과 진화 양상
2021-07-30 • Sands Lab • Recent attack methods and evolution patterns of the Lazarus group •
https://drive.google.com/file/d/18jFDyBvBEazOzXLkWRJNxatJTxV1UoMw/view
Attachments
Sands Lab tracked Lazarus Group document malware collected from malwares.com that impersonated companies including Rheinmetall, GM, and Airbus. The campaign used malicious Word documents with similar VBA scripts, Base64 encoded payloads, split script components for antivirus evasion, sandbox delay logic, C2 downloads, and explorer.exe injection. The report links the tradecraft to earlier Lazarus HWP attacks from 2019 and assesses the corporate lure documents as likely Lazarus activity.