#SyncHole
Incident/Operation
Operation SyncHole was a Lazarus Group campaign conducted from November 2024 through March 2025 against at least six South Korean organizations in software, IT, finance, semiconductor manufacturing, and telecommunications. Attackers combined watering-hole access with exploitation of vulnerabilities in widely used South Korean software, executed malware inside legitimate processes, and abused an Innorix Agent flaw for lateral movement. The campaign deployed updated variants of ThreatNeedle, Agamemnon downloader, wAgent, SIGNBT, and COPPERHEDGE. Its focus on the domestic software ecosystem and selective exploitation enabled system compromise and possible data theft across multiple industrial targets.
-
3
Tagged Reports
-
2
Unique Authors
-
22
Active Days