logo

Lazarus_Group__2018__Lazarus_Campaign_Targeting_Cryptocurrencies.pdf

ID: 84811a8a-73df-4805-a029-5807b4f234eb

STIX ID: report--84811a8a-73df-4805-a029-5807b4f234eb

Threat Score

80/100

Uploaded: 2026-08-15

Published Date: 2018-03-15

Last Modified Date: 2018-03-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro analyzes a Lazarus group campaign that uses a PowerShell-based RATANKBA backdoor delivered via malicious Microsoft Office documents, CHM files and script downloaders (cryptocurrency-themed lures). The backdoor communicates with a controller/C2 via HTTP to receive tasks (command execution, DLL injection, interval changes, kill) and upload victim data; researchers recovered backend logs, attacker profiles tied to Korean-language users and cryptocurrency transactions, and published IoCs (hashes) plus defensive mitigations.