WithSecure-Lazarus-No-Pineapple-Threat-Intelligence-Report-2023.pdf
ID: 04858091-77e1-4b4f-96ad-de80c893766a
STIX ID: report--04858091-77e1-4b4f-96ad-de80c893766a
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2023-01-31
Last Modified Date: 2023-01-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
WithSecure's 'No Pineapple' report documents a Q4 2022 DPRK-attributed intrusion (Lazarus Group) that exploited Zimbra vulnerabilities to gain initial access to medical research, energy, and supply-chain targets; operators deployed webshells, tunnelling/proxy tools (Plink, 3Proxy, Stunnel), and malware including Dtrack, GREASE, and a QT-based backdoor (acres.exe), used Impacket for remote execution and Mimikatz for credential theft, and exfiltrated roughly 100 GB of data while exhibiting nation-state TTPs and operational patterns consistent with UTC+9 working hours.
