Lazarus_Group__2020__ADEO-Lazarus-APT38.pdf
ID: 38c0ad69-5543-4b52-941c-f531f437b260
STIX ID: report--38c0ad69-5543-4b52-941c-f531f437b260
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** This public ADEO DFIR report analyzes a Lazarus/APT38 campaign ("Pot Of Gold", Apr 2020) that exploited SharePoint RCE (CVE-2019-0604) to deploy PowerShell Empire and custom RAT/ELECTRICFISH tooling, perform credential theft and lateral movement, and deploy ATM-targeting DLLs to intercept transactions; the report includes technical malware analysis, MITRE ATT&CK mapping, and IOCs (hashes, IPs, domains).
