Lazarus group evolves its infection chain with old and new malware
ID: c7b86715-d4c1-5274-83cf-c699184cc3cc
STIX ID: report--c7b86715-d4c1-5274-83cf-c699184cc3cc
Feed Name: Securelist by Kaspersky
This report documents a Lazarus APT recruitment-themed campaign (DeathNote / Operation DreamJob) that delivered trojanized VNC utilities and archive lures to targets in aerospace, defense, cryptocurrency and a nuclear-related organization. The attackers used a complex, multi-stage infection chain — including Ranid Downloader, trojanized VNC/side-loaded DLLs, MISTPEN, RollMid, LPEClient, CookieTime, ServiceChanger, Charamel Loader and the new CookiePlus modular downloader/plugins — to achieve persistence, lateral movement, and payload delivery via WordPress-based PHP C2 servers; the report includes TTPs and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
