Deep-Dive: The Lazarus Group
2020-02-06 • Bushidotoken •
https://blog.bushidotoken.net/2020/02/deep-dive-lazarus-group.html
The source provides a narrative history of Lazarus Group operations, including the Bangladesh Bank SWIFT theft attempt and WannaCry ransomware activity. It describes the Bangladesh Bank case as a phishing-enabled intrusion that reached systems used for SWIFT transactions and attempted to move roughly one billion dollars through prepared accounts. The report also discusses WannaCry’s use of the EternalBlue SMB exploit to spread widely across vulnerable Windows systems. Although the article is broad, it gives defenders context on Lazarus’ progression from espionage and destructive attacks to financially motivated intrusions and wormable ransomware.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.cpomagazine.com/cyb… | 2020-02-06 | 2020-02-06 |