Unit180 (Lazarus) targets Japan!
2021-05-06 • 0xthreatintel •
The source links Unit180/Lazarus targeting of Japan to the VSingle and ValeforBeta malware families and compares them with Torisma and LCPDot from Operation Dream Job. The analysis says both malware samples share exported functions and DllEntryPoint logic with earlier Lazarus tooling, including buffer-overflow setup, anti-VM, and anti-analysis routines. It also highlights pipe-based command-and-control setup, shell-command execution, file operations, and a dedicated function for C2 operations. The report’s value is the code-level comparison tying the Japan-focused activity to prior Unit180 tradecraft rather than a broad campaign overview.