Lazarus Group Targets More Cryptocurrency Exchanges and FinTech Companies
ID: 8abc33b2-32f5-4581-861a-3be302848278
STIX ID: report--8abc33b2-32f5-4581-861a-3be302848278
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2018-08-06
Last Modified Date: 2018-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Intezer's analysis documents a Lazarus Group campaign that lures cryptocurrency and FinTech targets with a fake "Investment Proposal.doc" containing an obfuscated VBA macro which drops a bespoke RAT; the report provides static and dynamic analysis (decryption routines, API resolving, persistence via Startup shortcut), lists command IDs and capabilities, embeds TLS/certificate artifacts and an RSA private key, and publishes IoCs (sample hashes and multiple C2 IP addresses), concluding the group remains active and focused on crypto theft.
