Lazarus 그룹의 윈도우 웹 서버 대상 공격 사례 분석

2025-03-05 Ahnlab Analysis of Lazarus Group Attacks Targeting Windows Web Servers

https://asec.ahnlab.com/ko/86631/

Thumbnail for Lazarus 그룹의 윈도우 웹 서버 대상 공격 사례 분석

AhnLab ASEC analyzes Lazarus intrusions against Windows web servers that were compromised and reused as command-and-control infrastructure. The report describes attacks on South Korean web servers where the actor installed web shells and C2 proxy scripts, including ASP-based components on IIS servers, to relay traffic between malware and next-stage C2 systems. It also notes cases involving LazarLoader malware and privilege-escalation tooling, making the activity relevant for defenders monitoring exposed Windows web applications, web-shell deployment, proxy C2 behavior, and follow-on loader execution.

Related Actors

Related Reports

« Back