logo

CryptoCore-Lazarus-Clearsky.pdf

ID: 3c7cf2bd-d89e-4f3b-b59f-1ea4df8c824f

STIX ID: report--3c7cf2bd-d89e-4f3b-b59f-1ea4df8c824f

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2021-05-24

Last Modified Date: 2021-05-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report consolidates and compares research from ClearSky, F‑SECURE, JPCERT/CC, NTT Security and others on the CryptoCore/CryptoMimic campaign that targeted cryptocurrency exchanges and wallets worldwide; through IOC overlaps, near-identical VBS downloader scripts, detailed binary-code matches (RC4/Base64 routines and command parsers), and YARA rule reuse the authors reaffirm attribution to North Korea's LAZARUS APT and conclude a high-probability linkage of the campaign to Lazarus.