logo

Lazarus hackers breach six companies in watering hole attacks

ID: 9afc8f2c-49d1-5b52-91ad-b535bb585c98

STIX ID: report--9afc8f2c-49d1-5b52-91ad-b535bb585c98

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-04-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Operation SyncHole was a Lazarus-led watering-hole espionage campaign (Nov 2024–Feb 2025) that compromised legitimate South Korean media sites to redirect victims to fake vendor pages and exploit widely used software (Cross EX and Innorix Agent). The attackers injected shellcode into a legitimate SyncHost.exe process to load the ThreatNeedle backdoor (capable of 37 commands) and deployed additional tools (LPEClient, wAgent/Agamemnon, Innorix Abuser, SIGNBT/Copperhedge) for profiling, lateral movement, and reconnaissance; Kaspersky attributed the activity to Lazarus, observed modular and stealthier tooling, and reported that patches were released and a non-exploited zero-day (KVE-2024-0014) in Innorix Agent was responsibly disclosed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.