logo

Lazarus_Group__2018__cta-2018-0116.pdf

ID: 59349ce4-492c-4d7c-809c-e657c0e77f5a

STIX ID: report--59349ce4-492c-4d7c-809c-e657c0e77f5a

Threat Score

82/100

Uploaded: 2026-08-15

Published Date: 2018-01-15

Last Modified Date: 2018-01-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future reports that North Korean state-sponsored actors (Lazarus Group) conducted a late-2017 spear-phishing campaign against South Korean cryptocurrency exchanges, users, and a student group using malicious Hangul (.hwp) documents that embedded a Ghostscript exploit (CVE-2017-8291). The attackers delivered Destover-derived infostealer payloads (with 32/64-bit DLLs), used IP-based C2 infrastructure, provided YARA detection rules and IOC hashes, and likely leveraged code reuse and obfuscation (including transliterated Chinese function names) to hinder attribution.