logo

Lazarus_Group__2020__ESET_Lazarus-supply-chain-attack-SouthKorea_11-16-2020.pdf

ID: 49c0dc04-a10a-487e-bccf-93a22fcedaf6

STIX ID: report--49c0dc04-a10a-487e-bccf-93a22fcedaf6

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2024-01-04

Last Modified Date: 2024-01-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET documents a targeted supply-chain attack by the Lazarus APT in South Korea that leverages compromised websites using WIZVERA VeraPort to push signed, Themida-protected malware (multi-stage dropper → loader → downloader → RAT). The attackers used stolen code-signing certificates to bypass VeraPort signature checks, and the report includes detailed behavioral analysis, network C2 protocol artifacts, cryptographic routines, and extensive IoCs (file hashes, cert serials, C2 URLs, mutex) along with mitigation guidance such as enabling hash verification in VeraPort configurations.