Operation SyncHole: Lazarus APT goes back to the well
ID: 95dcc915-c7e4-50fe-a1ca-b010167b5daf
STIX ID: report--95dcc915-c7e4-50fe-a1ca-b010167b5daf
Feed Name: Securelist by Kaspersky
Kaspersky describes “Operation SyncHole”, a Lazarus-led APT campaign (Nov 2024–Feb 2025) targeting South Korean organizations via watering‑hole redirects and exploitation of local software (Cross EX and Innorix Agent) to deploy modular backdoors and loaders (ThreatNeedle variants, SIGNBT, wAgent, COPPERHEDGE, Agamemnon). The actors leveraged supply‑chain and zero‑day/one‑day vulnerabilities for initial access and lateral movement, used compromised Korean websites as C2, and the report provides detailed TTPs, IOCs, and vendor/agency disclosures and patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
