logo

Lazarus_Group__2017__blog.pdf

ID: 6b760c8b-c9e3-43f5-aaf3-7804c20b1652

STIX ID: report--6b760c8b-c9e3-43f5-aaf3-7804c20b1652

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2017-12-20

Last Modified Date: 2017-12-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Overview:** Proofpoint researchers attribute a series of multi-stage, financially motivated campaigns to the Lazarus Group that leverage cryptocurrency-related lures to deploy a new PowerShell implant (PowerRatankba), Gh0st RAT variants to harvest wallet/exchange credentials, and a point-of-sale threat (RatankbaPOS) aimed at stealing card data during peak shopping periods.