Lazarus_Group__2020__ESET_Lazarus-supply-chain-attack-SouthKorea_11-16-2020.pdf
ID: 49c0dc04-a10a-487e-bccf-93a22fcedaf6
STIX ID: report--49c0dc04-a10a-487e-bccf-93a22fcedaf6
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2024-01-04
Last Modified Date: 2024-01-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET documents a targeted supply-chain attack by the Lazarus APT in South Korea that leverages compromised websites using WIZVERA VeraPort to push signed, Themida-protected malware (multi-stage dropper → loader → downloader → RAT). The attackers used stolen code-signing certificates to bypass VeraPort signature checks, and the report includes detailed behavioral analysis, network C2 protocol artifacts, cryptographic routines, and extensive IoCs (file hashes, cert serials, C2 URLs, mutex) along with mitigation guidance such as enabling hash verification in VeraPort configurations.
