logo

Lazarus_Group__2020__ADEO-Lazarus-APT38.pdf

ID: 38c0ad69-5543-4b52-941c-f531f437b260

STIX ID: report--38c0ad69-5543-4b52-941c-f531f437b260

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2026-02-13

Last Modified Date: 2026-02-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** This public ADEO DFIR report analyzes a Lazarus/APT38 campaign ("Pot Of Gold", Apr 2020) that exploited SharePoint RCE (CVE-2019-0604) to deploy PowerShell Empire and custom RAT/ELECTRICFISH tooling, perform credential theft and lateral movement, and deploy ATM-targeting DLLs to intercept transactions; the report includes technical malware analysis, MITRE ATT&CK mapping, and IOCs (hashes, IPs, domains).