logo

Lazarus_Group__2022__MalwareBytes_NorthKoreas-Lazarus-APT-Windows-Update-GitHub_01-27-2022.pdf

ID: 5ccefb57-5800-4840-b3b1-eb98b2679c02

STIX ID: report--5ccefb57-5800-4840-b3b1-eb98b2679c02

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2022-02-21

Last Modified Date: 2022-02-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Malwarebytes Threat Intelligence describes a January 2022 Lazarus APT campaign that used Lockheed Martin-themed malicious Word documents with macros to deploy a multi-stage loader: macros hijack KernelCallbackTable to run shellcode that decrypts and maps DLLs, injects into explorer.exe and RuntimeBroker, drops a signed wuaueng.dll which is executed via the Windows Update client (wuauclt.exe), and uses GitHub repositories as a C2 channel; the report includes component breakdowns, code snippets, network and file IOCs (hashes, domains, filenames), and attribution to Lazarus.