Lazarus_Group__2022__Kaspersky_Lazarus-Trojanized-DeFi-delivering-malware_03-31-2022.pdf
ID: 3454cf11-0a75-4e85-9a21-96b43ddb6fcb
STIX ID: report--3454cf11-0a75-4e85-9a21-96b43ddb6fcb
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2022-04-01
Last Modified Date: 2022-04-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report describes a Lazarus APT campaign in which attackers distributed a Trojanized DeFi Wallet installer (DeFi-App.exe) that drops and launches a disguised backdoor (GoogleChrome.exe). The analysis covers the multi-stage infection flow, payload structure and behavior (RC4+Base64 C2, extensive backdoor commands including discovery, file operations, remote execution, and timestomping), compromised South Korean web servers used as staged C2s, code and script overlaps linking the activity to the Lazarus/CookieTime/ThreatNeedle clusters, MITRE ATT&CK mapping, and a list of IoCs for detection and takedown.
