logo

Lazarus_Group__2019__LAZARUS_GAZE_APT38.pdf

ID: 98758de9-7af6-42f8-9f22-b9dc0a10fb2c

STIX ID: report--98758de9-7af6-42f8-9f22-b9dc0a10fb2c

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2019-11-07

Last Modified Date: 2019-11-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes a Lazarus (APT38) spear-phishing campaign that used malicious Microsoft Word attachments with doubly base64‑encoded first‑stage payloads to drop a DLL implant which enumerates hosts, collects system and drive info, achieves persistence via a thumbnail.lnk Start Menu shortcut, and beacons encrypted/compressed data to HTTP-based C2; a backend VBScript on compromised sites gates and selectively serves second‑stage payloads (whitelist/blacklist logic). The writeup includes technical disassembly, ATT&CK technique mappings, IoCs (SHA256s, domain, IP, file locations) and detection guidance.