Lazarus hackers breach six companies in watering hole attacks
ID: 9afc8f2c-49d1-5b52-91ad-b535bb585c98
STIX ID: report--9afc8f2c-49d1-5b52-91ad-b535bb585c98
Feed Name: Bleeping Computer
Operation SyncHole was a Lazarus-led watering-hole espionage campaign (Nov 2024–Feb 2025) that compromised legitimate South Korean media sites to redirect victims to fake vendor pages and exploit widely used software (Cross EX and Innorix Agent). The attackers injected shellcode into a legitimate SyncHost.exe process to load the ThreatNeedle backdoor (capable of 37 commands) and deployed additional tools (LPEClient, wAgent/Agamemnon, Innorix Abuser, SIGNBT/Copperhedge) for profiling, lateral movement, and reconnaissance; Kaspersky attributed the activity to Lazarus, observed modular and stealthier tooling, and reported that patches were released and a non-exploited zero-day (KVE-2024-0014) in Innorix Agent was responsibly disclosed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
