logo

Lazarus_Group__2020__Kaspersky_Lazarus-covets-COVID-19-related-intelligence_12-23-2020.pdf

ID: 75a983c8-f77d-4517-a0e2-c1e2ab06cffc

STIX ID: report--75a983c8-f77d-4517-a0e2-c1e2ab06cffc

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2024-01-04

Last Modified Date: 2024-01-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Kaspersky documents two Lazarus group intrusions targeting COVID-19-related organizations — a Ministry of Health compromised with an in-memory wAgent backdoor and a pharmaceutical company infected with Bookcode via a supply-chain or targeted intrusion — describing infection chains, post-exploitation activity (credential dumping, lateral movement, AD enumeration), C2 infrastructure, and IoCs to support detection and remediation.