Lazarus_Group__2022__Ahnlab-Lazarus-attack-group-exploits-INITECH-process_04-18-2022.pdf
ID: 33914513-1023-4985-9b77-a51b8f1fb349
STIX ID: report--33914513-1023-4985-9b77-a51b8f1fb349
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2022-04-29
Last Modified Date: 2022-04-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
An AhnLab technical analysis describes a Lazarus Group campaign in early 2022 that abused the INITECH INISAFE CrossWeb EX process by injecting SCSKAppLink.dll into the signed inisafecrosswebexsvc.exe binary to download and execute additional malware; ~47 organizations including defense and chemical sector companies were impacted and the report exposes MD5 hashes and C2/URL IOCs.
