Lazarus_Group__2016__Operation-Blockbuster-Loaders-Installers-and-Uninstallers-Report.pdf
ID: bbbaf4f2-75e4-4c0b-9d9c-1471c93c916b
STIX ID: report--bbbaf4f2-75e4-4c0b-9d9c-1471c93c916b
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Novetta Operation Blockbuster reverse‑engineering report analyzes Lazarus Group tooling (installers, loaders, uninstallers) used to deliver and persist multiple malware families (Romeo*, Delta*, Whiskey*, PapaAlfa, etc.). It catalogs technical behaviors (resource‑embedded payloads, dynamic API loading, manual DLL mapping, service installation, suicide scripts, C2 protocols, payload storage formats), variant differences, and observed campaign artifacts and IOCs, providing actionable TTPs for detection and response.
