Uncover North Korean APT Group Lazarus Group — Attack Techniques and Money Laundering…
2023-10-13 • Shark Team •
SharkTeam profiles Lazarus as a North Korean financial-threat actor with BlueNorOff/APT38 focused on SWIFT and cryptocurrency theft and Andariel focused on South Korean targets. The report reviews Lazarus tradecraft across spear-phishing, watering-hole compromises, supply-chain attacks, SMB-based lateral movement, ransomware or destructive payloads, and SWIFT fraud, with examples including Sony Pictures, Bangladesh Bank, Polish financial-sector watering holes, and LinkedIn recruiter lures against cryptocurrency workers. It also discusses malware behaviors such as RC4, AES, Spritz and custom encryption, false TLS, IRC and HTTP communications, MBR or partition damage, self-deleting scripts, and cryptocurrency laundering through mixers, cross-chain transfers, bridges, and exchanges. Treat it as a broad Lazarus tactics and money-laundering overview rather than evidence of a single new intrusion.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | stake.com | 2023-09-05 | 2025-12-31 |
| URL | https://discord.gg/jGH9xXCjDZ | 2023-10-13 | 2024-06-13 |
| HASH | b94a13586828f8f3474f7b89755f5e7… | 2022-08-17 | 2023-10-13 |