#INISafeWeb

Vulnerability/Target

2021-07-08 • Analysis of Lazarus malware abusing Non-ActiveX Module in South Korea

INISAFE Web EX Client is a South Korean Non-ActiveX security component from INITECH. Lazarus-linked malware checked for the installed client, injected code into its legitimate process, and used the compromised execution context to download and run additional payloads from compromised Korean web infrastructure.

Tagged Reports

« Back