#MovieCoin
Incident/Operation
Operation MovieCoin was a Lazarus campaign observed in June and July 2019 using malicious HWP documents tailored to South Korean targets. Lures included a cryptocurrency investment contract and a system-porting specification; embedded PostScript and shellcode exploited the document environment, downloaded 32-bit or 64-bit DLL payloads disguised as media files, and presented credible decoy content. The resulting bot collected host and user information, accepted commands, downloaded and executed additional files, and could delay activity. Shared payload behavior and PostScript patterns connected the waves to earlier Lazarus operations, while the cryptocurrency lure suggested a possible financial objective.
-
3
Tagged Reports
-
1
Unique Authors
-
34
Active Days