T-APT-15

2018-03-07 • TencentLazarus APT组织最新活动揭露

Tencent's Yujian Threat Intelligence Center uses T-APT-15 as its internal tracking designation for the Lazarus Group, a North Korea-linked APT that Tencent describes as having a history of attacks against South Korea, the United States, and global financial institutions, including the Sony Pictures breach, the Bangladesh Bank SWIFT heist, cryptocurrency exchanges, and suspected links to WannaCry. In a 2018 report, Tencent documented T-APT-15/Lazarus spear-phishing cryptocurrency exchanges and other targets with decoy Word documents, themed around agreements, IT security, and exchange security analysis, that embedded a Flash exploit for CVE-2018-4878, a use-after-free vulnerability enabling arbitrary memory read and write. Successful exploitation injected shellcode into explorer.exe, which fetched further payloads from attacker-controlled infrastructure and ultimately deployed a variant of the FALLCHILL remote-access trojan, linked to Lazarus through code, command-dispatch, and protocol similarities as well as Korean-language RAT resources. Tencent assessed that the group's targeting had expanded from energy, military, and government sectors toward financial institutions, particularly cryptocurrency exchanges.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster