logo

WithSecure-Lazarus-No-Pineapple-Threat-Intelligence-Report-2023.pdf

ID: 04858091-77e1-4b4f-96ad-de80c893766a

STIX ID: report--04858091-77e1-4b4f-96ad-de80c893766a

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2023-01-31

Last Modified Date: 2023-01-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
WithSecure's 'No Pineapple' report documents a Q4 2022 DPRK-attributed intrusion (Lazarus Group) that exploited Zimbra vulnerabilities to gain initial access to medical research, energy, and supply-chain targets; operators deployed webshells, tunnelling/proxy tools (Plink, 3Proxy, Stunnel), and malware including Dtrack, GREASE, and a QT-based backdoor (acres.exe), used Impacket for remote execution and Mimikatz for credential theft, and exfiltrated roughly 100 GB of data while exhibiting nation-state TTPs and operational patterns consistent with UTC+9 working hours.