logo

Lazarus_Group__2021__CryptoCore-Lazarus-Clearsky.pdf

ID: 374a9e3b-d6e3-470a-ab81-59f5b5772339

STIX ID: report--374a9e3b-d6e3-470a-ab81-59f5b5772339

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2021-05-25

Last Modified Date: 2021-05-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Attributing Attacks Against Crypto Exchanges to LAZARUS – North Korea**: This report aggregates ClearSky, F‑SECURE, JPCERT/CC and NTT Security findings on a three‑year campaign (CryptoCore/CryptoMimic) that exfiltrated cryptocurrency from exchanges and wallets, demonstrates overlapping IOCs and nearly identical VBS downloaders, shows code‑level and behavioral matches across RATs and stealers (unique RC4, Base64 routines, packer usage, process injection), validates F‑SECURE YARA rules against confirmed LAZARUS samples (ESET, Kaspersky), and concludes with a high probability attribution to the North Korean LAZARUS APT.