logo

Lazarus_Group__2021__Lazarus_Group_Recruitment_Threat_Hunters_vs_Head_Hunters.pdf

ID: 7fe40b19-c2f4-43b5-aa76-8487325f1738

STIX ID: report--7fe40b19-c2f4-43b5-aa76-8487325f1738

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2021-04-28

Last Modified Date: 2021-04-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Positive Technologies documents a September–November 2020 Lazarus Group spearphishing campaign that lured victims with fake General Dynamics job offers to deliver malicious Office/PDF documents containing VBA macros; these deployed the Agamemnon downloader and CommsCacher backdoor, enabling network reconnaissance, persistence (LNK autoruns, service creation, account creation), lateral movement and partial control of a pharmaceutical company's infrastructure. The report maps observed behaviors to MITRE ATT&CK, provides IOCs (file hashes, domains, IPs, C2 lists), artifacts used for forensic reconstruction, and links the activity to known Lazarus tooling and prior campaigns.