Catching Lazarus: Threat Intelligence to Real Detection Logic - Part One
2020-09-25 • With Secure •
T1566.003 – Phishing: Spearphishing via Service The Lazarus Group gained initial access on the target organization by sending a phishing document to a systems administrator via their personal LinkedIn account. To demonstrate this, we downloaded and executed a malicious Word document[7] associated with the Lazarus Group's campaign to investigate the behavior of the embedded payload. Breaking down the Lazarus Group campaign with MITRE The following sections in this document map the key attack techniques used by the Lazarus Group into the relevant MITRE ATT&CK® Matrix tactics. This makes detection based on TTPs more reliable as blue teams can detect malicious activity even when IOCs change.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | t.ly | 2020-09-25 | 2023-05-11 |
| IPv4 | 66.181.166.15 | 2020-06-24 | 2021-05-24 |