Lazarus_Group__2021__CryptoCore-Lazarus-Clearsky.pdf
ID: 374a9e3b-d6e3-470a-ab81-59f5b5772339
STIX ID: report--374a9e3b-d6e3-470a-ab81-59f5b5772339
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2021-05-25
Last Modified Date: 2021-05-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Attributing Attacks Against Crypto Exchanges to LAZARUS – North Korea**: This report aggregates ClearSky, F‑SECURE, JPCERT/CC and NTT Security findings on a three‑year campaign (CryptoCore/CryptoMimic) that exfiltrated cryptocurrency from exchanges and wallets, demonstrates overlapping IOCs and nearly identical VBS downloaders, shows code‑level and behavioral matches across RATs and stealers (unique RC4, Base64 routines, packer usage, process injection), validates F‑SECURE YARA rules against confirmed LAZARUS samples (ESET, Kaspersky), and concludes with a high probability attribution to the North Korean LAZARUS APT.
