logo

Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America

ID: b3a652e8-5a22-4fa7-a939-f4ce23d86f18

STIX ID: report--b3a652e8-5a22-4fa7-a939-f4ce23d86f18

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2018-11-30

Last Modified Date: 2018-11-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Trend Micro describes a September 2018 Lazarus/Bluenoroff campaign that installed a modularized backdoor on financial institution systems in Latin America using a service-launched loader (AuditCred.dll/ROptimizer.dll) which decrypts an in-memory backdoor (Msadoz<n>.dll) and an encrypted .mui configuration to retrieve C2 addresses; the backdoor supports file discovery, download, process management, code injection, proxying and both active and passive command channels, and the report includes C2 IPs and mitigation recommendations.