Microsoft Word - Lazarus Report.docx
ID: bc074aad-b61d-4635-a2de-7aa66e6e0e17
STIX ID: report--bc074aad-b61d-4635-a2de-7aa66e6e0e17
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-01-20
Last Modified Date: 2019-01-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes a spyware implant linked to APT37 used in a 1 January 2019 campaign against the South Korean Unification Ministry, documenting anti-analysis protections (VMProtect, VM and debugger detection), persistence via a dropped HncChecker.dll installed as a service, second-stage DLLs for different architectures, keystroke logging to C:\ProgramData\Hnc\userdata.cab, and strings indicating command-and-control, file transfer and remote-command capabilities; the report includes file metadata and MD5 hashes as IOCs.
