Lazarus Group: Unveiling the Notorious APT Cyber Threat
2024-01-21 • Foresiet •
https://foresiet.com/blog/lazarus-group-apt-cyber-threat-activity/
The Foresiet overview profiles Lazarus Group, also known as Hidden Cobra, as a North Korean APT active since at least 2009. It says recent activity has included attacks on banks and cryptocurrency exchanges in the United States, South Korea, Japan, and other countries, using malware such as ransomware and banking trojans alongside phishing and spear phishing. The source maps the group to techniques including command and scripting interpreters, ingress tool transfer, indirect command execution, valid accounts, C2 based exfiltration, and data destruction. Detection material in the article includes example YARA and Sigma content, but the main CTI value is the high level summary of Lazarus targeting and TTPs.