Selective Pisces
2022-09-26 • Paloalto Networks • Hunting for Unsigned DLLs to Find APTs
Selective Pisces is Palo Alto Networks Unit 42’s designation for a North Korean threat group also identified in its reporting as Lazarus Group, ZINC, and APT-C-26. Unit 42 publicly used the name in September 2022 while describing threat-hunting results involving malicious unsigned DLLs. The group abused signed third-party software, including DreamSecurity MagicLine4NX, to launch malicious payloads and used DLL side-loading to evade detection. Its execution chain wrote a malicious DLL, copied the legitimate Windows Remote Management host process into a randomly named ProgramData directory, and relied on that trusted binary to load the payload. The actor also established persistence by placing a malicious DLL under a name expected by the Windows print-spooler service. This tradecraft combines legitimate-software abuse, search-order hijacking, encrypted or high-entropy payloads, nonstandard filesystem locations, and system-service execution to conceal North Korean operations.
-
60
Related Actors
-
690
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Selective Pisces reports only