Selective Pisces

2022-09-26 • Paloalto NetworksHunting for Unsigned DLLs to Find APTs

Selective Pisces is Palo Alto Networks Unit 42’s designation for a North Korean threat group also identified in its reporting as Lazarus Group, ZINC, and APT-C-26. Unit 42 publicly used the name in September 2022 while describing threat-hunting results involving malicious unsigned DLLs. The group abused signed third-party software, including DreamSecurity MagicLine4NX, to launch malicious payloads and used DLL side-loading to evade detection. Its execution chain wrote a malicious DLL, copied the legitimate Windows Remote Management host process into a randomly named ProgramData directory, and relied on that trusted binary to load the payload. The actor also established persistence by placing a malicious DLL under a name expected by the Windows print-spooler service. This tradecraft combines legitimate-software abuse, search-order hijacking, encrypted or high-entropy payloads, nonstandard filesystem locations, and system-service execution to conceal North Korean operations.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster