IoC Update of Lazarus Group’s Recent Attack Campaign Targeting South Korea

2025-10-28 S2W

https://s2w.inc/en/resource/detail/941

Thumbnail for IoC Update of Lazarus Group’s Recent Attack Campaign Targeting South Korea

S2W TALON analyzed recent Lazarus malware samples targeting South Korean entities and identified three loader variants plus the FastCopy v3.6.1 utility. The loaders recovered encrypted or encoded payloads in memory using AES or XOR operations, including keys derived from execution arguments, filenames, hardcoded strings, and an XOR key reused from the 2023 LazarLoader campaign. The payload set included privilege-escalation malware referencing public UACMe source code and screenshot/logging malware that triggered on keyboard or mouse activity. S2W also noted FastCopy reuse consistent with Lazarus activity since at least 2022, while the initial infection vector remained unconfirmed and watering hole attacks or known vulnerabilities were described only as plausible routes.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7fba2051fecbafa51bbfbc807fa1683… 2025-10-28 2025-10-28
HASH 016b8de3f7356da0d91da9f36f74ccf… 2025-10-28 2025-10-28
HASH c0e50b5795e99f89e5dcb54c46b6537… 2025-10-28 2025-10-28
HASH c58cd3b53f535f0388deefe77b918d8b 2025-10-28 2025-10-28
HASH b70d8ca638fcb088d260155a547c681… 2025-10-28 2025-10-28
HASH 7f5e0edaf3fbf38a5635d4cd0b84b57a 2025-10-28 2025-10-28
HASH 79ac1eda882973d2cd86c844a184cb8… 2025-10-28 2025-10-28

Related Actors

Related Reports

« Back