CryptoCore-Lazarus-Clearsky.pdf
ID: 3c7cf2bd-d89e-4f3b-b59f-1ea4df8c824f
STIX ID: report--3c7cf2bd-d89e-4f3b-b59f-1ea4df8c824f
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2021-05-24
Last Modified Date: 2021-05-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report consolidates and compares research from ClearSky, F‑SECURE, JPCERT/CC, NTT Security and others on the CryptoCore/CryptoMimic campaign that targeted cryptocurrency exchanges and wallets worldwide; through IOC overlaps, near-identical VBS downloader scripts, detailed binary-code matches (RC4/Base64 routines and command parsers), and YARA rule reuse the authors reaffirm attribution to North Korea's LAZARUS APT and conclude a high-probability linkage of the campaign to Lazarus.
