#Blacksmith

Incident/Operation

2023-12-11 • Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang

Operation Blacksmith is a Lazarus Group campaign disclosed in December 2023, with tradecraft overlapping the North Korean subgroup Andariel, also tracked as Onyx Sleet. It opportunistically exploited internet-facing enterprise infrastructure, including Log4Shell-vulnerable systems, and affected manufacturing, agriculture, and physical-security organizations in several regions from at least March 2023. The campaign introduced three DLang-based malware families: the Telegram-controlled NineRAT, the DLRAT remote-access trojan, and the BottomLoader downloader, alongside the custom HazyLoad proxy.

Tagged Reports

« Back