Lazarus 그룹의 NukeSped 악성코드 분석 보고서
2021-11-10 • Ahnlab • NukeSped malware analysis report by Lazarus Group •
AhnLab analyzes Lazarus Group attacks observed from around 2020 onward that used the NukeSped backdoor. The report traces distribution through malicious email attachments and watering-hole activity, then describes NukeSped modules such as update, file management, keylogging, SOCKS tunneling, screen capture, information gathering, and port forwarding components. It also covers attacker commands and additional malware installed during later stages, including credential theft from browsers and Outlook, clipboard and window-text collection, MAC-time manipulation, launchers, and DarkComet RAT. The source frames NukeSped as a multi-function backdoor supporting Lazarus intrusion operations.