logo

Lazarus_Group__2013__Dark_Seoul_Cyberattack_1.pdf

ID: 85500fe6-8180-45b1-a5e9-d720c4fc093a

STIX ID: report--85500fe6-8180-45b1-a5e9-d720c4fc093a

Threat Score

70/100

Uploaded: 2026-08-15

Published Date: 2013-06-28

Last Modified Date: 2013-06-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes the March 20, 2013 Dark Seoul campaign that disrupted major South Korean banks and broadcasters by using spearphishing and a compromised website to deliver an Internet Explorer exploit (CVE-2012-1889), deploy downloaders and backdoors, perform local DNS poisoning for credential harvesting, and ultimately execute a cross-platform wiper (Trojan.Jokra) that overwrote MBRs and rendered systems unusable; the authors conclude the campaign caused high impact at scale (~48,000 infected machines) despite relatively low technical sophistication compared with contemporary APTs.