logo

Lazarus_Group__2017__Group-IB_Lazarus.pdf

ID: 743bfd39-9587-4d70-ba41-b1edf7ebdb0f

STIX ID: report--743bfd39-9587-4d70-ba41-b1edf7ebdb0f

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2017-05-29

Last Modified Date: 2017-05-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Group-IB analyzed Lazarus (aka DarkSeoul) operations targeting banks and regulators — detailing a modular implant family (Recon, Dropper, Loader, Client_RAT, Client_TrafficForwarder, Server_RAT, Server_TrafficForwarder, Backend_Listener), a three-tier SSL-wrapped C2 using compromised hosts and SoftEther VPN for anonymization, concrete IOCs (IP lists, SoftEther endpoints, certificate fingerprints, malware hashes), examples of exploit vectors (Flash/Silverlight/JBoss/Liferay) and practical recommendations for detection and response.