Lazarus_Group__2013__dissecting-operation-troy.pdf
ID: bb7cf337-3cd9-4d65-9f83-63b3e562735a
STIX ID: report--bb7cf337-3cd9-4d65-9f83-63b3e562735a
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2013-07-04
Last Modified Date: 2013-07-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Labs' analysis of "Operation Troy" (Dark Seoul) describes a sustained APT campaign from 2009–2013 that conducted covert espionage against South Korean military and government networks, maintained encrypted IRC/HTTP command-and-control infrastructure, exfiltrated sensitive documents, and culminated in a destructive MBR-wiping event on March 20, 2013; the report details the malware components, toolchain (bs.dll/payload.dll), compile paths and IOCs, and attributes activity to a group using Roman-themed markers (NewRomanic Cyber Army Team).
