logo

Lazarus_Group__2022__Symantec_Lazarus-Targets-Chemical-Sector_04-14-2022.pdf

ID: 9a3bf462-f2cb-46c4-9f0a-6b23a7e21431

STIX ID: report--9a3bf462-f2cb-46c4-9f0a-6b23a7e21431

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2022-04-20

Last Modified Date: 2022-04-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that the Lazarus APT (tracked as Pompilus / Operation Dream Job) conducted a targeted espionage campaign against organizations—primarily in South Korea's chemical sector—using fake job lures that deploy malicious HTM files which are copied into signed Trojanized DLL/CPL components (e.g., scskaplink.dll, final.cpl) to load shellcode, download backdoors, dump credentials, move laterally via WMI/MagicLine, establish persistence (scheduled tasks/services), and deploy post-compromise tools; the report includes detailed TTPs and IOCs (SHA-256 hashes, IPs, domains, URLs, filenames, and service names) and recommends vigilance and updated protections.