Living off the Land (LOTL) attacks: How North Korea’s Lazarus Group Hackers Exploited Windows
2025-02-23 • System Weakness •
The article describes Lazarus-linked Operation 99 activity against developers and Web3 organizations in Europe, using trusted platforms and Windows utilities to avoid early detection. The reported chain begins with trojanized GitHub software, then abuses built-in tools such as certutil.exe, mshta.exe, PowerShell, scheduled tasks, and registry run keys for payload download, persistence, and stealth. The source links the activity to command-and-control servers found during fake-job-scam research and says the campaign aimed to steal financial assets and proprietary technology.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | aad3b435b51404eeaad3b435b51404ee | 2025-02-23 | 2025-02-23 |
Related Actors
Related Reports
2025-03-25 •
60% Match
Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup
JPCERT
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month
2025-03-10 •
60% Match
#NPM
#Lazarus
#T1027.013
#T1082
#T1119
#T1005
#T1041
#T1608.001
#T1195.002
#T1083
#T1059.007
#T1204.002
#T1555.003
#T1105
#T1657
#T1555.001
#T1546.016
#T1217
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month