Lazarus_Group__2021__Lazarus_Group_Recruitment_Threat_Hunters_vs_Head_Hunters.pdf
ID: 7fe40b19-c2f4-43b5-aa76-8487325f1738
STIX ID: report--7fe40b19-c2f4-43b5-aa76-8487325f1738
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2021-04-28
Last Modified Date: 2021-04-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Positive Technologies documents a September–November 2020 Lazarus Group spearphishing campaign that lured victims with fake General Dynamics job offers to deliver malicious Office/PDF documents containing VBA macros; these deployed the Agamemnon downloader and CommsCacher backdoor, enabling network reconnaissance, persistence (LNK autoruns, service creation, account creation), lateral movement and partial control of a pharmaceutical company's infrastructure. The report maps observed behaviors to MITRE ATT&CK, provides IOCs (file hashes, domains, IPs, C2 lists), artifacts used for forensic reconstruction, and links the activity to known Lazarus tooling and prior campaigns.
