Lazarus_Group__2013__Dark_Seoul_Cyberattack_1.pdf
ID: 85500fe6-8180-45b1-a5e9-d720c4fc093a
STIX ID: report--85500fe6-8180-45b1-a5e9-d720c4fc093a
Threat Score
70/100
Uploaded: 2026-08-15
Published Date: 2013-06-28
Last Modified Date: 2013-06-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes the March 20, 2013 Dark Seoul campaign that disrupted major South Korean banks and broadcasters by using spearphishing and a compromised website to deliver an Internet Explorer exploit (CVE-2012-1889), deploy downloaders and backdoors, perform local DNS poisoning for credential harvesting, and ultimately execute a cross-platform wiper (Trojan.Jokra) that overwrote MBRs and rendered systems unusable; the authors conclude the campaign caused high impact at scale (~48,000 infected machines) despite relatively low technical sophistication compared with contemporary APTs.
