Living off the Land (LOTL) attacks: How North Korea’s Lazarus Group Hackers Exploited Windows

2025-02-23 System Weakness

https://systemweakness.com/living-off-the-land-lotl-attacks-how-north-korea-lazarus-group-hackers-exploited-windows-a46ee8fb945f

The article describes Lazarus-linked Operation 99 activity against developers and Web3 organizations in Europe, using trusted platforms and Windows utilities to avoid early detection. The reported chain begins with trojanized GitHub software, then abuses built-in tools such as certutil.exe, mshta.exe, PowerShell, scheduled tasks, and registry run keys for payload download, persistence, and stealth. The source links the activity to command-and-control servers found during fake-job-scam research and says the campaign aimed to steal financial assets and proprietary technology.

Indicators of Compromise

Type Value First Seen Last Seen
HASH aad3b435b51404eeaad3b435b51404ee 2025-02-23 2025-02-23

Related Actors

Related Reports

« Back