Lazarus_Group__2020__Kaspersky_Lazarus-covets-COVID-19-related-intelligence_12-23-2020.pdf
ID: 75a983c8-f77d-4517-a0e2-c1e2ab06cffc
STIX ID: report--75a983c8-f77d-4517-a0e2-c1e2ab06cffc
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2024-01-04
Last Modified Date: 2024-01-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Kaspersky documents two Lazarus group intrusions targeting COVID-19-related organizations — a Ministry of Health compromised with an in-memory wAgent backdoor and a pharmaceutical company infected with Bookcode via a supply-chain or targeted intrusion — describing infection chains, post-exploitation activity (credential dumping, lateral movement, AD enumeration), C2 infrastructure, and IoCs to support detection and remediation.
