Lazarus_Group__2017__Group-IB_Lazarus.pdf
ID: 743bfd39-9587-4d70-ba41-b1edf7ebdb0f
STIX ID: report--743bfd39-9587-4d70-ba41-b1edf7ebdb0f
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2017-05-29
Last Modified Date: 2017-05-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Group-IB analyzed Lazarus (aka DarkSeoul) operations targeting banks and regulators — detailing a modular implant family (Recon, Dropper, Loader, Client_RAT, Client_TrafficForwarder, Server_RAT, Server_TrafficForwarder, Backend_Listener), a three-tier SSL-wrapped C2 using compromised hosts and SoftEther VPN for anonymization, concrete IOCs (IP lists, SoftEther endpoints, certificate fingerprints, malware hashes), examples of exploit vectors (Flash/Silverlight/JBoss/Liferay) and practical recommendations for detection and response.
