APT trends report Q3 2021
2021-10-26 • Kaspersky •
Kaspersky's Q3 2021 APT trends report says Lazarus attacked the defense industry with the MATA malware framework, using a trojanized application trusted by the intended victim. The execution chain began with a downloader that fetched additional malware from compromised C2 servers, and Kaspersky obtained several MATA components, including plugins. The report links the campaign more strongly to Lazarus through MATA evolution, stolen certificate use, and downloader ties to TangoDaiwbo, then separately notes updated DeathNote activity against a South Korean think tank and an IT asset monitoring vendor.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | quicktech.com | 2021-10-26 | 2021-10-26 |
Related Actors
Related Reports
Shares tags: Trend, Andariel, Kimsuky • Same author: Kaspersky
Shares tags: Trend, Andariel, Kimsuky • Same author: Kaspersky
Shares tags: Trend, Andariel, Kimsuky
Shares tags: Trend, Andariel, Kimsuky
Shares tags: Trend, Andariel, Kimsuky
2025-10-23 •
60% Match
#Trend
#Andariel
#Kimsuky
#Lazarus
#T1204.004
#T1574.002
#T1564.006
#T1027.006
Shares tags: Trend, Andariel, Kimsuky