F-Secure
ID: 0a79a1fe-c3a9-40b2-b0bb-fcc7a144124b
STIX ID: report--0a79a1fe-c3a9-40b2-b0bb-fcc7a144124b
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2020-08-20
Last Modified Date: 2020-08-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
F-Secure's tactical intelligence report documents a Lazarus Group campaign (since at least 2018) targeting cryptocurrency organisations via LinkedIn-spearphish malicious documents that deploy macros → mshta/VBScript → PowerShell to fetch and execute sophisticated implants. The analysis details custom PE loaders and main implants (LSSVC.dll, NTUSER.cat) injected into lsass/explorer, network backdoors, persistence via Security Support Provider registry changes, credential theft (Mimikatz), extensive IOC listings (hashes, C2 IPs/domains, bit.ly links) and detection guidance for blue teams.
