logo

Lazarus_Group__2021__Lazarus_campaign_TTPs_and_evolution_AT_T_Alien_Labs.pdf

ID: 99e4c06a-be60-462b-a5af-011749c38a35

STIX ID: report--99e4c06a-be60-462b-a5af-011749c38a35

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2021-07-27

Last Modified Date: 2021-07-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** AT&T Alien Labs attributes a spring 2021 campaign to the Lazarus APT targeting engineering job candidates and defense contractors in the U.S. and Europe via malicious Office documents; the macros use base64-encoded payload components, rename and copy legitimate Windows utilities (e.g., certutil, explorer) to evade EDR, perform decoding and injection/launch (Mavinject or explorer), contact hardcoded C2 domains, and the report includes YARA rules, IDS/TDR detections, and numerous IOCs for detection and hunting.