Lazarus_Group__2022__Zscaler-Naver-ending-game-Lazarus-APT_04-26-2022.pdf
ID: 2a60eb1c-ba8e-4c81-85f8-008ed0c9c032
STIX ID: report--2a60eb1c-ba8e-4c81-85f8-008ed0c9c032
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2022-04-29
Last Modified Date: 2022-04-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Zscaler ThreatLabz documents a Lazarus APT campaign targeting South Korea that uses Naver- and other local-themed spear-phishing (macro and CHM lures) to deliver a multi-stage malware chain which drops a packed payload, establishes persistence, retrieves C2 domains (via Dropbox-hosted pointers) and exfiltrates machine identifiers; the report provides detailed technical analysis, infrastructure correlation for high-confidence attribution to Lazarus, and extensive IoCs (hashes, domains, IPs, and email addresses) for detection and mitigation.
