Lazarus_Group__2017__blog.pdf
ID: 6b760c8b-c9e3-43f5-aaf3-7804c20b1652
STIX ID: report--6b760c8b-c9e3-43f5-aaf3-7804c20b1652
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2017-12-20
Last Modified Date: 2017-12-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Overview:** Proofpoint researchers attribute a series of multi-stage, financially motivated campaigns to the Lazarus Group that leverage cryptocurrency-related lures to deploy a new PowerShell implant (PowerRatankba), Gh0st RAT variants to harvest wallet/exchange credentials, and a point-of-sale threat (RatankbaPOS) aimed at stealing card data during peak shopping periods.
