20231013_Lazarus_OP.Dream_Magic.pdf
ID: a77d03d3-9416-4b34-9420-9b04fa7d4e59
STIX ID: report--a77d03d3-9416-4b34-9420-9b04fa7d4e59
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2023-10-13
Last Modified Date: 2023-10-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary
AhnLab presents "Operation Dream Magic", a seven‑month analysis of watering‑hole attacks that abused the MagicLine client to distribute Lazarus-linked malware. The report details 105 confirmed detections across ~40 organizations (IT, defense, media, finance, etc.), multiple case studies showing DLL side‑loading and fileless payloads, C2 domains/IPs, malware hashes, and behavioral indicators; it concludes attribution to Lazarus based on shared reassembly code and SYS-file generation patterns and provides concrete mitigation steps (remove/update MagicLine, enable behavior-based detection, extend log retention).
