#Lazardoor
Malware/Tool
2022-10-06 • 라자루스 그룹 DLL Side-Loading 기법 이용 (mi.dll)
A South Korean court investigation detected a file as Trojan/Win.Lazardoor on a Seoul Central District Court server and found additional malicious files on internet virtual PCs, although the court publicly said attribution to Lazarus was not conclusive. In another incident, malicious threads were injected into svchost.exe, which connected to attacker-controlled addresses, while vulnerable-driver activity involving PROCEXP152.SYS was observed around attempts to disable the V3 security product. The same activity renamed and deleted malicious files for anti-forensics.
-
3
Tagged Reports
-
2
Unique Authors
-
425
Active Days