IoC Update of Lazarus Group’s Recent Attack Campaign Targeting South Korea

2025-10-28 S2W

https://s2w.inc/en/resource/detail/941

Thumbnail for IoC Update of Lazarus Group’s Recent Attack Campaign Targeting South Korea

S2W TALON analyzed recent Lazarus malware samples targeting South Korean entities and identified three loader variants plus the FastCopy v3.6.1 utility. The loaders recovered encrypted or encoded payloads in memory using AES or XOR operations, including keys derived from execution arguments, filenames, hardcoded strings, and an XOR key reused from the 2023 LazarLoader campaign. The payload set included privilege-escalation malware referencing public UACMe source code and screenshot/logging malware that triggered on keyboard or mouse activity. S2W also noted FastCopy reuse consistent with Lazarus activity since at least 2022, while the initial infection vector remained unconfirmed and watering hole attacks or known vulnerabilities were described only as plausible routes.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d9b7a2bdda52e08fb1cbd018aafb9f1a 2025-10-28 2025-10-28
HASH 8d2efe5dba73e84f308fb0b954dbec12 2025-10-28 2025-10-28
HASH ffc693542abc34331e967da85fc2221e 2025-10-28 2025-10-28
HASH c58cd3b53f535f0388deefe77b918d8b 2025-10-28 2025-10-28
HASH 66165f3705d558235cd1dbe5f41c2866 2025-10-28 2025-10-28
HASH 7f5e0edaf3fbf38a5635d4cd0b84b57a 2025-10-28 2025-10-28
HASH bdadbf4af5b65131b081323417c36c82 2025-10-28 2025-10-28

Related Actors

Related Reports

« Back