Lazarus APT updates its toolset in watering hole attacks

2025-04-24 Kaspersky

https://securelist.com/operation-synchole-watering-hole-attacks-by-lazarus/116326/

Thumbnail for Lazarus APT updates its toolset in watering hole attacks

Lazarus targeted at least six South Korean organizations in software, IT, finance, semiconductor manufacturing, and telecommunications through Operation SyncHole, combining watering-hole delivery with exploitation of South Korea-specific security software. The initial chain involved visits to South Korean online media sites, redirection to attacker-controlled infrastructure, suspected Cross EX exploitation, execution of legitimate SyncHost.exe, and injection of a ThreatNeedle variant. The campaign also used an Innorix Agent vulnerability for lateral movement and introduced updated Lazarus tooling including ThreatNeedle, wAgent, SIGNBT, COPPERHEDGE, and Agamemnon downloader variants. The activity matters because it shows Lazarus adapting its toolset and exploiting locally deployed Korean software to reach high-value South Korean sectors.

Indicators of Compromise

Type Value First Seen Last Seen
HASH dc0e17879d66ea9409cdf679bfea388c 2025-04-24 2025-04-24
HASH f1bcb4c5aa35220757d09fc5feea193b 2025-04-24 2025-04-24
HASH 2d47ef0089010d9b699cd1bbbc66f10a 2025-04-24 2025-04-24
URL https://www.rsdf.kr/wp-content/… 2025-04-24 2025-04-24
URL https://thek-portal.com/eng/car… 2025-04-24 2025-04-24
URL https://htns.com/eng/skin/membe… 2025-04-24 2025-04-24
URL http://dream.bluit.gethompy.com… 2025-04-24 2025-04-24
URL http://www.shcpump.com/admin/fo… 2025-04-24 2025-04-24
URL https://kadsm.org/skin/board/ba… 2025-04-24 2025-04-24
URL http://bluekostec.com/eng/commu… 2025-04-24 2025-04-24
URL https://builsf.com/inc/left.php 2025-04-24 2025-04-24
DOMAIN builsf.com 2025-04-24 2025-04-24
DOMAIN dream.bluit.gethompy.com 2025-04-24 2025-04-24
DOMAIN bluekostec.com 2025-04-24 2025-04-24
DOMAIN htns.com 2025-04-24 2025-04-24
DOMAIN kadsm.org 2025-04-24 2025-04-24
DOMAIN thek-portal.com 2025-04-24 2025-04-24

Related Actors

Related Reports

2025-08-13 • 42% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1218.010 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1573 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004
Shares tags: Lazarus, T1082, T1140
« Back