logo

20231013_Lazarus_OP.Dream_Magic.pdf

ID: a77d03d3-9416-4b34-9420-9b04fa7d4e59

STIX ID: report--a77d03d3-9416-4b34-9420-9b04fa7d4e59

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2023-10-13

Last Modified Date: 2023-10-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary AhnLab presents "Operation Dream Magic", a seven‑month analysis of watering‑hole attacks that abused the MagicLine client to distribute Lazarus-linked malware. The report details 105 confirmed detections across ~40 organizations (IT, defense, media, finance, etc.), multiple case studies showing DLL side‑loading and fileless payloads, C2 domains/IPs, malware hashes, and behavioral indicators; it concludes attribution to Lazarus based on shared reassembly code and SYS-file generation patterns and provides concrete mitigation steps (remove/update MagicLine, enable behavior-based detection, extend log retention).