APT trends report Q3 2021

2021-10-26 Kaspersky

https://securelist.com/apt-trends-report-q3-2021/104708/

Thumbnail for APT trends report Q3 2021

Kaspersky's Q3 2021 APT trends report says Lazarus attacked the defense industry with the MATA malware framework, using a trojanized application trusted by the intended victim. The execution chain began with a downloader that fetched additional malware from compromised C2 servers, and Kaspersky obtained several MATA components, including plugins. The report links the campaign more strongly to Lazarus through MATA evolution, stolen certificate use, and downloader ties to TangoDaiwbo, then separately notes updated DeathNote activity against a South Korean think tank and an IT asset monitoring vendor.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN quicktech.com 2021-10-26 2021-10-26

Related Actors

First seen: Jul 2017
Last seen: Jun 2026

Related Reports

« Back