logo

Lazarus_Group__2016__Operation-Blockbuster-Loaders-Installers-and-Uninstallers-Report.pdf

ID: bbbaf4f2-75e4-4c0b-9d9c-1471c93c916b

STIX ID: report--bbbaf4f2-75e4-4c0b-9d9c-1471c93c916b

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2026-02-13

Last Modified Date: 2026-02-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Novetta Operation Blockbuster reverse‑engineering report analyzes Lazarus Group tooling (installers, loaders, uninstallers) used to deliver and persist multiple malware families (Romeo*, Delta*, Whiskey*, PapaAlfa, etc.). It catalogs technical behaviors (resource‑embedded payloads, dynamic API loading, manual DLL mapping, service installation, suicide scripts, C2 protocols, payload storage formats), variant differences, and observed campaign artifacts and IOCs, providing actionable TTPs for detection and response.