He is everywhere
First seen: 2016-02 •
Last seen: 2026-06
#VeraPort • 2020-11
Lazarus abused the WIZVERA VeraPort software distribution workflow used by South Korean government and banking sites, compromising supported websites and replacing legitimate bundled installers with malware. The attack relied on VeraPort accepting any valid code-signing certificate rather than verifying signer identity, with observed Delfino.exe and MagicLineNPIZ.exe samples masquerading as South Korean security software and signed with certificates issued to ALEXIS SECURITY GROUP and DREAM SECURITY USA.
4
Related Reports
1
Affected Countries
67
Months Since
He is everywhere