logo

Lazarus_Group__2022__Qianxin_Analysis_of_the_Suspected_Lazarus_Attack_Activities_against_South_Korean_Companies_04-11-2022.pdf

ID: 588434cb-2935-4e57-bf83-1d97dc3d3b83

STIX ID: report--588434cb-2935-4e57-bf83-1d97dc3d3b83

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2022-04-29

Last Modified Date: 2022-04-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This intelligence analysis describes a large spearphishing campaign against South Korean companies that uses malicious Office/CHM documents (exploiting CVE-2017-0199) to deploy multi-stage malware which performs process injection, UAC bypass (RPC-based), sandbox and AV detection (checks for v3l4sp.exe and AYAgent), persistence via registry startup keys, Defender exclusion, and C2 communications (naveicoipg.online, naveicoipc.tech and Dropbox links); the report includes code snippets, observed IOCs (hashes, domains, URLs), and attributes the activity to the Lazarus APT based on technique and infrastructure overlaps.