#Lazardoor

Malware/Tool

2023-02-27 • 공공 기관 및 대학 등에 널리 사용하는 공인인증서 소프트웨어 취약점을 이용한 Lazarus 공격 그룹 공격 사례

A South Korean court investigation detected a file as Trojan/Win.Lazardoor on a Seoul Central District Court server and found additional malicious files on internet virtual PCs, although the court publicly said attribution to Lazarus was not conclusive. In another incident, malicious threads were injected into svchost.exe, which connected to attacker-controlled addresses, while vulnerable-driver activity involving PROCEXP152.SYS was observed around attempts to disable the V3 security product. The same activity renamed and deleted malicious files for anti-forensics.

Tagged Reports

« Back