Lazarus_Group__2022__Symantec_Lazarus-Targets-Chemical-Sector_04-14-2022.pdf
ID: 9a3bf462-f2cb-46c4-9f0a-6b23a7e21431
STIX ID: report--9a3bf462-f2cb-46c4-9f0a-6b23a7e21431
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2022-04-20
Last Modified Date: 2022-04-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that the Lazarus APT (tracked as Pompilus / Operation Dream Job) conducted a targeted espionage campaign against organizations—primarily in South Korea's chemical sector—using fake job lures that deploy malicious HTM files which are copied into signed Trojanized DLL/CPL components (e.g., scskaplink.dll, final.cpl) to load shellcode, download backdoors, dump credentials, move laterally via WMI/MagicLine, establish persistence (scheduled tasks/services), and deploy post-compromise tools; the report includes detailed TTPs and IOCs (SHA-256 hashes, IPs, domains, URLs, filenames, and service names) and recommends vigilance and updated protections.
