logo

Lazarus_Group__2022__North_Korea_s_Lazarus_APT_leverages_Windows_Update_client_GitHub_in_latest_campaign_Malwarebytes_Labs.pdf

ID: 63465d75-8f45-416e-8d2e-b5c8f98a751e

STIX ID: report--63465d75-8f45-416e-8d2e-b5c8f98a751e

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2022-02-10

Last Modified Date: 2022-02-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Lazarus APT conducted a targeted spear-phishing campaign (malicious Lockheed Martin job-themed documents) that used sophisticated techniques including KernelCallbackTable control-flow hijacking in VBA macros, staged DLL injection, persistence via a Windows Update shortcut invoking wuauclt.exe, and GitHub repositories as a C2 channel; the report includes full static and dynamic analysis, multiple payload hashes, domains, and a GitHub account used by the operator.