Lazarus_Group__2018__cta-2018-0116.pdf
ID: 59349ce4-492c-4d7c-809c-e657c0e77f5a
STIX ID: report--59349ce4-492c-4d7c-809c-e657c0e77f5a
Threat Score
82/100
Uploaded: 2026-08-15
Published Date: 2018-01-15
Last Modified Date: 2018-01-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future reports that North Korean state-sponsored actors (Lazarus Group) conducted a late-2017 spear-phishing campaign against South Korean cryptocurrency exchanges, users, and a student group using malicious Hangul (.hwp) documents that embedded a Ghostscript exploit (CVE-2017-8291). The attackers delivered Destover-derived infostealer payloads (with 32/64-bit DLLs), used IP-based C2 infrastructure, provided YARA detection rules and IOC hashes, and likely leveraged code reuse and obfuscation (including transliterated Chinese function names) to hinder attribution.
