logo

The_Lazarus_Constellation.pdf

ID: bbc2fde4-bfcb-48ed-a017-2ae0b1e0c878

STIX ID: report--bbc2fde4-bfcb-48ed-a017-2ae0b1e0c878

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2020-02-28

Last Modified Date: 2020-02-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
A technical intelligence study of the Lazarus constellation (North Korean APT) documenting its evolution, motives (esp. financially motivated heists), tooling and tradecraft across 2007–2019; includes detailed malware analyses (SQCSVC, SWPSVC, injectors, keyloggers), encryption and C2 methods (Fake-TLS), exploited CVEs, IOCs, YARA/Snort detection rules, a sample dataset and classification methodology, plus incident response guidance and mitigation recommendations.