Lazarus_Group__2022__MalwareBytes_NorthKoreas-Lazarus-APT-Windows-Update-GitHub_01-27-2022.pdf
ID: 5ccefb57-5800-4840-b3b1-eb98b2679c02
STIX ID: report--5ccefb57-5800-4840-b3b1-eb98b2679c02
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2022-02-21
Last Modified Date: 2022-02-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Malwarebytes Threat Intelligence describes a January 2022 Lazarus APT campaign that used Lockheed Martin-themed malicious Word documents with macros to deploy a multi-stage loader: macros hijack KernelCallbackTable to run shellcode that decrypts and maps DLLs, injects into explorer.exe and RuntimeBroker, drops a signed wuaueng.dll which is executed via the Windows Update client (wuauclt.exe), and uses GitHub repositories as a C2 channel; the report includes component breakdowns, code snippets, network and file IOCs (hashes, domains, filenames), and attribution to Lazarus.
