Lazarus Under The Hood
First seen: 2017-04 •
Last seen: 2026-05
#BROU • 2016-10
Banco República/BROU was included in the same global banking watering-hole activity that used compromised financial-sector websites to target a small set of selected IP addresses belonging mostly to banks and related organizations. The linked analyses describe redirects tied to Mexican regulator and Uruguayan bank sites, payload delivery through eye-watch[.]in, Ratankba and Hacktool activity, encrypted remote-access capabilities, and Lazarus-like code or infrastructure overlaps.
3
Related Reports
1
Affected Countries
116
Months Since
Lazarus Under The Hood