Lazarus APT updates its toolset in watering hole attacks
2025-04-24 • Kaspersky •
https://securelist.com/operation-synchole-watering-hole-attacks-by-lazarus/116326/
Lazarus targeted at least six South Korean organizations in software, IT, finance, semiconductor manufacturing, and telecommunications through Operation SyncHole, combining watering-hole delivery with exploitation of South Korea-specific security software. The initial chain involved visits to South Korean online media sites, redirection to attacker-controlled infrastructure, suspected Cross EX exploitation, execution of legitimate SyncHost.exe, and injection of a ThreatNeedle variant. The campaign also used an Innorix Agent vulnerability for lateral movement and introduced updated Lazarus tooling including ThreatNeedle, wAgent, SIGNBT, COPPERHEDGE, and Agamemnon downloader variants. The activity matters because it shows Lazarus adapting its toolset and exploiting locally deployed Korean software to reach high-value South Korean sectors.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | dc0e17879d66ea9409cdf679bfea388c | 2025-04-24 | 2025-04-24 |
| HASH | f1bcb4c5aa35220757d09fc5feea193b | 2025-04-24 | 2025-04-24 |
| HASH | 2d47ef0089010d9b699cd1bbbc66f10a | 2025-04-24 | 2025-04-24 |
| URL | https://www.rsdf.kr/wp-content/… | 2025-04-24 | 2025-04-24 |
| URL | https://thek-portal.com/eng/car… | 2025-04-24 | 2025-04-24 |
| URL | https://htns.com/eng/skin/membe… | 2025-04-24 | 2025-04-24 |
| URL | http://dream.bluit.gethompy.com… | 2025-04-24 | 2025-04-24 |
| URL | http://www.shcpump.com/admin/fo… | 2025-04-24 | 2025-04-24 |
| URL | https://kadsm.org/skin/board/ba… | 2025-04-24 | 2025-04-24 |
| URL | http://bluekostec.com/eng/commu… | 2025-04-24 | 2025-04-24 |
| URL | https://builsf.com/inc/left.php | 2025-04-24 | 2025-04-24 |
| DOMAIN | builsf.com | 2025-04-24 | 2025-04-24 |
| DOMAIN | dream.bluit.gethompy.com | 2025-04-24 | 2025-04-24 |
| DOMAIN | bluekostec.com | 2025-04-24 | 2025-04-24 |
| DOMAIN | htns.com | 2025-04-24 | 2025-04-24 |
| DOMAIN | kadsm.org | 2025-04-24 | 2025-04-24 |
| DOMAIN | thek-portal.com | 2025-04-24 | 2025-04-24 |