Dissecting Lazarus's operation target for cryptocurrency business

2020-02-05 • Kaspersky •

https://github.com/theseongsu/presentation/blob/main/K-CTI2020_Lazarus.pdf

Attachments

K-CTI2020_Lazarus.pdf (4 MB)

Thumbnail for Dissecting Lazarus's operation target for cryptocurrency business

Seongsu Park’s K-CTI 2020 Lazarus slides emphasize that threat intelligence is broader than IOC lists alone. The extracted slide text shows a loader and C2 chain involving update.exe, a .NET loader, injection into iexplorer.exe, a tainted loader, and encrypted configuration files. The presentation argues for TTP-oriented detection, including ATT&CK and Sigma-based approaches, rather than relying only on domains, IPs, and hashes.

Related Actors

Related Reports

« Back