Lazarus_Group__2022__Qianxin_Analysis_of_the_Suspected_Lazarus_Attack_Activities_against_South_Korean_Companies_04-11-2022.pdf
ID: 588434cb-2935-4e57-bf83-1d97dc3d3b83
STIX ID: report--588434cb-2935-4e57-bf83-1d97dc3d3b83
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2022-04-29
Last Modified Date: 2022-04-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This intelligence analysis describes a large spearphishing campaign against South Korean companies that uses malicious Office/CHM documents (exploiting CVE-2017-0199) to deploy multi-stage malware which performs process injection, UAC bypass (RPC-based), sandbox and AV detection (checks for v3l4sp.exe and AYAgent), persistence via registry startup keys, Defender exclusion, and C2 communications (naveicoipg.online, naveicoipc.tech and Dropbox links); the report includes code snippets, observed IOCs (hashes, domains, URLs), and attributes the activity to the Lazarus APT based on technique and infrastructure overlaps.
