logo

Lazarus_Group__2022__Ahnlab-Lazarus-attack-group-exploits-INITECH-process_04-18-2022.pdf

ID: 33914513-1023-4985-9b77-a51b8f1fb349

STIX ID: report--33914513-1023-4985-9b77-a51b8f1fb349

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2022-04-29

Last Modified Date: 2022-04-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
An AhnLab technical analysis describes a Lazarus Group campaign in early 2022 that abused the INITECH INISAFE CrossWeb EX process by injecting SCSKAppLink.dll into the signed inisafecrosswebexsvc.exe binary to download and execute additional malware; ~47 organizations including defense and chemical sector companies were impacted and the report exposes MD5 hashes and C2/URL IOCs.