logo

BAE Systems Threat Research Blog: Lazarus & Watering-hole attacks

ID: 55023a26-68b9-45fe-ad03-f007274ef232

STIX ID: report--55023a26-68b9-45fe-ad03-f007274ef232

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2017-02-28

Last Modified Date: 2017-02-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BAE Systems analyses a campaign of watering‑hole attacks that compromised bank supervisory and bank websites (notably knf.gov.pl, www.cnbv.gob.mx and others) to serve Silverlight/Flash exploits (CVE‑2016‑0034) and deliver malware; the report includes malware/sample analysis (packed with Enigma Protector, double‑RC4 decryption), MD5 hashes, C2 IP addresses, and global IP whitelists targeting financial institutions, and recommends applying patches and blocking compromised domains.