Dissecting Lazarus's operation target for cryptocurrency business
2020-02-05 • Kaspersky •
https://github.com/theseongsu/presentation/blob/main/K-CTI2020_Lazarus.pdf
Attachments
K-CTI2020_Lazarus.pdf (4 MB)
Seongsu Park’s K-CTI 2020 Lazarus slides emphasize that threat intelligence is broader than IOC lists alone. The extracted slide text shows a loader and C2 chain involving update.exe, a .NET loader, injection into iexplorer.exe, a tainted loader, and encrypted configuration files. The presentation argues for TTP-oriented detection, including ATT&CK and Sigma-based approaches, rather than relying only on domains, IPs, and hashes.
Related Actors
Related Reports
2021-12-21 •
60% Match
#DreamJob
#Dacls
#MATA
#AppleJeus
#FALLCHILL
#ThreatNeedle
#Manuscrypt
#DeathNote
#LPEClient
#AGAMEMNON
#Lazarus
#CookieTime
#Copperhedge
#Bookcode
Shares tags: AppleJeus, ThreatNeedle, Lazarus • Same author: Kaspersky
2021-10-09 •
60% Match
Multi-universe of adversary: multiple campaigns of the Lazarus group and their connections
Kaspersky
Shares tags: AppleJeus, ThreatNeedle, Lazarus • Same author: Kaspersky
2021-10-07 •
60% Match
Multi-universe of adversary: multiple campaigns of the Lazarus group and their connections
Kaspersky
Shares tags: AppleJeus, ThreatNeedle, Lazarus • Same author: Kaspersky
Shares tags: ThreatNeedle, Slides, Lazarus • Same author: Kaspersky
Shares tags: ThreatNeedle, Slides, Lazarus • Same author: Kaspersky
Shares tags: AppleJeus, Lazarus • Published within a month