logo

Lazarus group evolves its infection chain with old and new malware

ID: c7b86715-d4c1-5274-83cf-c699184cc3cc

STIX ID: report--c7b86715-d4c1-5274-83cf-c699184cc3cc

Feed Name: Securelist by Kaspersky

Threat Score
90/100

Date Published: 2024-12-19

Date Updated: 2026-04-29

Author: Vasily Berdnikov, Sojun Ryu

...
...

This report documents a Lazarus APT recruitment-themed campaign (DeathNote / Operation DreamJob) that delivered trojanized VNC utilities and archive lures to targets in aerospace, defense, cryptocurrency and a nuclear-related organization. The attackers used a complex, multi-stage infection chain — including Ranid Downloader, trojanized VNC/side-loaded DLLs, MISTPEN, RollMid, LPEClient, CookieTime, ServiceChanger, Charamel Loader and the new CookiePlus modular downloader/plugins — to achieve persistence, lateral movement, and payload delivery via WordPress-based PHP C2 servers; the report includes TTPs and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.