Lazarus_Group__2021__Lazarus_campaign_TTPs_and_evolution_AT_T_Alien_Labs.pdf
ID: 99e4c06a-be60-462b-a5af-011749c38a35
STIX ID: report--99e4c06a-be60-462b-a5af-011749c38a35
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2021-07-27
Last Modified Date: 2021-07-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** AT&T Alien Labs attributes a spring 2021 campaign to the Lazarus APT targeting engineering job candidates and defense contractors in the U.S. and Europe via malicious Office documents; the macros use base64-encoded payload components, rename and copy legitimate Windows utilities (e.g., certutil, explorer) to evade EDR, perform decoding and injection/launch (Mavinject or explorer), contact hardcoded C2 domains, and the report includes YARA rules, IDS/TDR detections, and numerous IOCs for detection and hunting.
