logo

Lazarus Group APT Targeting South Korean Users

ID: 58c0ceea-d714-5741-b97e-adc88d1f676e

STIX ID: report--58c0ceea-d714-5741-b97e-adc88d1f676e

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz documents a year-long spear-phishing campaign targeting users in South Korea that uses CHM and macro-laden documents to deploy a multi-stage dropper and payload (drops IntelRST.exe, retrieves C2 info from attacker-controlled Dropbox, and exfiltrates machine identifiers); researchers correlate reused infrastructure, passive DNS, and registrant data to attribute the activity with high confidence to the Lazarus APT and publish numerous IoCs (file hashes, domains, IPs, emails, PDB path).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.