Nation-State Actor’s Arsenal: An In-Depth Look at Lazarus’ ScoringMathTea

2025-11-17 0x0d4y

https://0x0d4y.blog/arsenal-analysis-of-a-nation-state-actor-an-in-depth-look-at-lazarus-scoringmathtea/

Thumbnail for Nation-State Actor’s Arsenal: An In-Depth Look at Lazarus’ ScoringMathTea

ScoringMathTea is analyzed as a C++ RAT attributed in the text to Lazarus and tied to ESET’s Gotta Fly instance of Operation DreamJob targeting UAV-related know-how from companies supporting Ukraine. The sample is a DLL that starts from DllMain, creates a thread for its main function, initializes configuration fields, stores its C2 URL through stack strings, and leaves null slots for additional C2 addresses. The reverse engineering details a custom runtime string deobfuscation routine, API hashing, PE export parsing, dynamic API resolution, Winsock initialization, and repeated API lookups used to conceal functionality from static inspection. Its main loop maintains C2 communication with a 60-second beacon while waiting for operator commands, supporting capabilities such as remote command execution and in-memory plugin loading.

Related Actors

Related Reports

2025-08-25 • 51% Match
#Lazarus #GolangGhost #T1059.003 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1071.001 #T1115 #T1083 #T1056.001 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1547.001 #T1059.001 #T1497.001 #T1219 #T1574.002 #T1562.001 #T1622 #T1027.002 #T1573.001 #T1190 #T1123 #T1132.002 #T1564.001 #T1548.002 #T1055.012 #T1027.007 #T1217 #T1106 #T1027.009 #T1036.003 #T1055.002 #T1036.007 #T1059.010 #T1136.001 #T1134.004 #T1614.001 #T1574.007 #T1098.007 #T1010 #T1071.004 #T1021.002 #T1021.006
Shares tags: Lazarus, T1071.001, T1622
« Back