#DeathNote

Incident/Operation

2023-04-11 • Perfect Smoke and Mirrors of Enemy: Following Lazarus group by tracking DeathNote campaign

DeathNote is an active Lazarus cluster, also known as Operation DreamJob or NukeSped, named for downloader modules using Dn.dll or Dn64.dll filenames. From 2018 it targeted cryptocurrency businesses with malicious Word documents and industry-themed decoys, then shifted around April 2020 toward automotive, academic, and defense-linked organizations in Eastern Europe and later broadened its infection methods. Its evolving chains have used macros, trojanized applications, multi-stage backdoors, DLL side-loading, memory-resident payloads, service abuse, and software vulnerabilities, reflecting persistent development and increasingly selective targeting.

Tagged Reports

« Back