IoC Update of Lazarus Group’s Recent Attack Campaign Targeting South Korea
2025-10-28 • S2W •
S2W TALON analyzed recent Lazarus malware samples targeting South Korean entities and identified three loader variants plus the FastCopy v3.6.1 utility. The loaders recovered encrypted or encoded payloads in memory using AES or XOR operations, including keys derived from execution arguments, filenames, hardcoded strings, and an XOR key reused from the 2023 LazarLoader campaign. The payload set included privilege-escalation malware referencing public UACMe source code and screenshot/logging malware that triggered on keyboard or mouse activity. S2W also noted FastCopy reuse consistent with Lazarus activity since at least 2022, while the initial infection vector remained unconfirmed and watering hole attacks or known vulnerabilities were described only as plausible routes.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d9b7a2bdda52e08fb1cbd018aafb9f1a | 2025-10-28 | 2025-10-28 |
| HASH | 8d2efe5dba73e84f308fb0b954dbec12 | 2025-10-28 | 2025-10-28 |
| HASH | ffc693542abc34331e967da85fc2221e | 2025-10-28 | 2025-10-28 |
| HASH | c58cd3b53f535f0388deefe77b918d8b | 2025-10-28 | 2025-10-28 |
| HASH | 66165f3705d558235cd1dbe5f41c2866 | 2025-10-28 | 2025-10-28 |
| HASH | 7f5e0edaf3fbf38a5635d4cd0b84b57a | 2025-10-28 | 2025-10-28 |
| HASH | bdadbf4af5b65131b081323417c36c82 | 2025-10-28 | 2025-10-28 |