Uncover North Korean APT Group Lazarus Group — Attack Techniques and Money Laundering…

2023-10-13 Shark Team

https://medium.com/@sharkteam/sharkteam-uncover-north-korean-apt-group-lazarus-group-attack-techniques-and-money-laundering-fff6d67c04fb

Thumbnail for Uncover North Korean APT Group Lazarus Group — Attack Techniques and Money Laundering…

SharkTeam profiles Lazarus as a North Korean financial-threat actor with BlueNorOff/APT38 focused on SWIFT and cryptocurrency theft and Andariel focused on South Korean targets. The report reviews Lazarus tradecraft across spear-phishing, watering-hole compromises, supply-chain attacks, SMB-based lateral movement, ransomware or destructive payloads, and SWIFT fraud, with examples including Sony Pictures, Bangladesh Bank, Polish financial-sector watering holes, and LinkedIn recruiter lures against cryptocurrency workers. It also discusses malware behaviors such as RC4, AES, Spritz and custom encryption, false TLS, IRC and HTTP communications, MBR or partition damage, self-deleting scripts, and cryptocurrency laundering through mixers, cross-chain transfers, bridges, and exchanges. Treat it as a broad Lazarus tactics and money-laundering overview rather than evidence of a single new intrusion.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN stake.com 2023-09-05 2025-12-31
URL https://discord.gg/jGH9xXCjDZ 2023-10-13 2024-06-13
HASH b94a13586828f8f3474f7b89755f5e7… 2022-08-17 2023-10-13

Related Reports

« Back