LAZARUS ARISEN
ID: 504d9817-9e82-55d7-a41d-92f4d6982ff7
STIX ID: report--504d9817-9e82-55d7-a41d-92f4d6982ff7
Feed Name: Group-IB Blog
Group-IB's report analyzes the Lazarus APT (linked to North Korea), documenting a shift from DDoS/espionage to financially motivated attacks against banks and SWIFT infrastructures; it describes a modular malware toolset, a three-tier SSL-encrypted C2 architecture (including use of SoftEther VPN), infection vectors (watering-hole sites), identified IoCs (IPs, ports, compromised domains), major incidents such as the 2016 Bangladesh Bank heist, and prescriptive mitigation recommendations for financial organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
