logo

F-Secure

ID: 0a79a1fe-c3a9-40b2-b0bb-fcc7a144124b

STIX ID: report--0a79a1fe-c3a9-40b2-b0bb-fcc7a144124b

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2020-08-20

Last Modified Date: 2020-08-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
F-Secure's tactical intelligence report documents a Lazarus Group campaign (since at least 2018) targeting cryptocurrency organisations via LinkedIn-spearphish malicious documents that deploy macros → mshta/VBScript → PowerShell to fetch and execute sophisticated implants. The analysis details custom PE loaders and main implants (LSSVC.dll, NTUSER.cat) injected into lsass/explorer, network backdoors, persistence via Security Support Provider registry changes, credential theft (Mimikatz), extensive IOC listings (hashes, C2 IPs/domains, bit.ly links) and detection guidance for blue teams.