logo

Lazarus_Group__2013__dissecting-operation-troy.pdf

ID: bb7cf337-3cd9-4d65-9f83-63b3e562735a

STIX ID: report--bb7cf337-3cd9-4d65-9f83-63b3e562735a

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2013-07-04

Last Modified Date: 2013-07-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Labs' analysis of "Operation Troy" (Dark Seoul) describes a sustained APT campaign from 2009–2013 that conducted covert espionage against South Korean military and government networks, maintained encrypted IRC/HTTP command-and-control infrastructure, exfiltrated sensitive documents, and culminated in a destructive MBR-wiping event on March 20, 2013; the report details the malware components, toolchain (bs.dll/payload.dll), compile paths and IOCs, and attributes activity to a group using Roman-themed markers (NewRomanic Cyber Army Team).