#ExtremeJob

Incident/Operation

2019-01-31 • 라자루스 APT 조직, 오퍼레이션 익스트림 잡(Extreme Job)으로 공격 수행

Extreme Job was a January 2019 Lazarus spear-phishing campaign that reused document-macro code and filenames seen in earlier operations. A malicious Word document, distributed through a compromised South Korean website, displayed a false compatibility message to persuade recipients to enable macros. The obfuscated macro decrypted and launched an additional executable disguised as a Java update component while also opening a legitimate decoy document, extending tradecraft previously observed in the group’s Arabian Night activity and supporting covert compromise of selected recipients.

Tagged Reports

« Back