#GREASE
Malware/Tool
2018-12-05 • STOLEN PENCIL Campaign Targets Academia
GREASE is custom malware used by Lazarus Group during a 2022 intrusion into medical research and technology organizations. Operators deployed a fresh version after moving laterally from a compromised Zimbra server to Windows systems. GREASE located administrator accounts, enabled the Windows guest account, created a support account, and supported credential harvesting through registry exports. Its use occurred alongside Dtrack, Mimikatz, Cobalt Strike, web shells, proxy tools, and tunneling software during reconnaissance and large-scale data theft.
-
3
Tagged Reports
-
3
Unique Authors
-
1,521
Active Days
Tagged Reports
2023-02-02
With Secure
2020-10-27
USCISA