Lazarus_Group__2020__ESET_Operation_Interception.pdf
ID: 6a5e1721-a31f-42ef-aba9-ffaed36a60fc
STIX ID: report--6a5e1721-a31f-42ef-aba9-ffaed36a60fc
Threat Score
78/100
Uploaded: 2026-08-15
Published Date: 2020-06-15
Last Modified Date: 2020-06-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET’s report describes "Operation In(ter)ception": a targeted spearphishing campaign (fake LinkedIn job offers) from Sep–Dec 2019 against European aerospace and military firms that installed a custom multistage malware chain (WMIC+XSL→certutil→Stage1 downloader→Stage2 modular backdoor→PowerShell DLL), used living-off-the-land techniques, code-signing for evasion, and exfiltrated data via a custom-signed Dropbox CLI; the paper includes technical analysis, IOCs, MITRE mappings, and circumstantial attribution links to Lazarus.
