Lazarus_Group__2018__Lazarus_Campaign_Targeting_Cryptocurrencies.pdf
ID: 84811a8a-73df-4805-a029-5807b4f234eb
STIX ID: report--84811a8a-73df-4805-a029-5807b4f234eb
Threat Score
80/100
Uploaded: 2026-08-15
Published Date: 2018-03-15
Last Modified Date: 2018-03-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro analyzes a Lazarus group campaign that uses a PowerShell-based RATANKBA backdoor delivered via malicious Microsoft Office documents, CHM files and script downloaders (cryptocurrency-themed lures). The backdoor communicates with a controller/C2 via HTTP to receive tasks (command execution, DLL injection, interval changes, kill) and upload victim data; researchers recovered backend logs, attacker profiles tied to Korean-language users and cryptocurrency transactions, and published IoCs (hashes) plus defensive mitigations.
