#GREASE

Malware/Tool

2023-02-02 • No Pineapple! - DPRK Targeting of Medical Research and Technology Sector

GREASE is custom malware used by Lazarus Group during a 2022 intrusion into medical research and technology organizations. Operators deployed a fresh version after moving laterally from a compromised Zimbra server to Windows systems. GREASE located administrator accounts, enabled the Windows guest account, created a support account, and supported credential harvesting through registry exports. Its use occurred alongside Dtrack, Mimikatz, Cobalt Strike, web shells, proxy tools, and tunneling software during reconnaissance and large-scale data theft.

Tagged Reports

« Back