Pompilus

2022-04-14 • SymantecLazarus Targets Chemical Sector

Pompilus is Symantec’s tracking name for the subset of North Korean Lazarus activity that conducts Operation Dream Job. Symantec applied the name while reporting in April 2022 on an espionage campaign against South Korean chemical and information-technology organizations, describing it as a continuation of activity first observed in August 2020. The operation uses fabricated job offers to persuade targets to open malicious links or attachments, with earlier campaigns reaching defense, government, and engineering personnel. In the 2022 intrusion set, attackers delivered malicious web files, injected trojanized libraries into legitimate software, deployed shellcode loaders and additional malware, moved laterally through Windows management tools, dumped credentials, created scheduled tasks for persistence, and used screenshot, proxy, file-copy, and transfer utilities. Symantec assessed that the campaign sought intellectual property useful to North Korea’s strategic chemical, engineering, and defense interests.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster