#JTrack

Malware/Tool

2021-10-19 • The Lazarus Group's Attack Operations Targeting Japan

Operation JTrack was a Lazarus Group campaign observed in September 2020 that compromised multiple organizations in Japan through an infected managed service provider. The operation deployed the VSingle and ValeforBeta remote-access trojans and used tools including Mimikatz and smbexec for lateral movement, 3Proxy, Plink, and Stunnel for remote access, WinRAR for collection, and timestomp and ProcDump for supporting actions. Compromised Japanese websites were also used as command-and-control infrastructure.

Tagged Reports

« Back