APT-Q-1
2023-03-14 • Qianxin • Lazarus Group(APT-Q-1)
APT-Q-1 is Qianxin's internal tracking designation for Lazarus, a threat group described as active since at least 2009. Qianxin characterizes the group as conducting espionage and financially motivated operations, initially emphasizing government targets and later expanding toward financial institutions, cryptocurrency businesses, and supply chains. Its tradecraft includes spearphishing, watering-hole attacks, destructive or ransomware payloads, exploitation for lateral movement, and remote-access tooling. In a 2024 recruitment-themed campaign assessed as possibly related to the group, operators used fabricated employer and developer identities on professional platforms to entice blockchain developers into running malicious project code. The code stole browser credentials and cryptocurrency-wallet data across Windows, Linux, and macOS and installed additional payloads. Qianxin treated the campaign attribution cautiously, based on infrastructure overlap and similarities in targeting and social engineering.
-
60
Related Actors
-
8
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster