Operation Blockbuster
2016-02-24 • Novetta •
Attachments
Novetta Operation Blockbuster documents Lazarus Group remote administration and content staging malware families uncovered during a broader industry investigation. The report explains the Romeo RAT families, Sierra spreaders, Joanap peer to peer staging components, Hotel webserver tooling, and Whiskey destructive malware used across the Lazarus toolset. It describes both client and server mode RAT behavior, file upload and download capability, command execution, and a naming scheme used to classify Lazarus malware by function.
Related Actors
Related Reports
Shares tags: Blockbuster, Lazarus • Published within a week
Shares tags: Blockbuster, Lazarus • Published within a week
Shares tags: Whitepaper, Lazarus
Shares tags: Whitepaper, Lazarus
Shares tags: Blockbuster, Lazarus
Shares tags: Blockbuster, Lazarus