Advanced Lazarus Memory-Only Toolset Deeply Analyzed by Fox-IT
ID: 07ffce26-d98c-54ac-a8e8-469675959659
STIX ID: report--07ffce26-d98c-54ac-a8e8-469675959659
Feed Name: securityonline.info
## Executive Summary Security researchers identified a sophisticated Lazarus-linked cyber espionage campaign targeting international financial entities that uses a three-stage, memory-only framework (DPAPILoader -> RemotePELoader -> RemotePE). The operation leverages DPAPI-based environmental keying for staged decryption, HellsGate remapping and ETW patching to evade EDR, in-memory remote access with plugin support and secure file destruction, and Namecheap-hosted infrastructure with Microsoft-like HTTP cookie fields; defenders are advised to focus on host-based behavioral detection and targeted network hunting for IOCs such as lassvc.dll service names, DPAPI-encrypted blobs, and SNI/DNS artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
