The_Lazarus_Constellation.pdf
ID: bbc2fde4-bfcb-48ed-a017-2ae0b1e0c878
STIX ID: report--bbc2fde4-bfcb-48ed-a017-2ae0b1e0c878
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2020-02-28
Last Modified Date: 2020-02-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
A technical intelligence study of the Lazarus constellation (North Korean APT) documenting its evolution, motives (esp. financially motivated heists), tooling and tradecraft across 2007–2019; includes detailed malware analyses (SQCSVC, SWPSVC, injectors, keyloggers), encryption and C2 methods (Fake-TLS), exploited CVEs, IOCs, YARA/Snort detection rules, a sample dataset and classification methodology, plus incident response guidance and mitigation recommendations.
