logo

Microsoft Word - Lazarus Report.docx

ID: bc074aad-b61d-4635-a2de-7aa66e6e0e17

STIX ID: report--bc074aad-b61d-4635-a2de-7aa66e6e0e17

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-01-20

Last Modified Date: 2019-01-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes a spyware implant linked to APT37 used in a 1 January 2019 campaign against the South Korean Unification Ministry, documenting anti-analysis protections (VMProtect, VM and debugger detection), persistence via a dropped HncChecker.dll installed as a service, second-stage DLLs for different architectures, keystroke logging to C:\ProgramData\Hnc\userdata.cab, and strings indicating command-and-control, file transfer and remote-command capabilities; the report includes file metadata and MD5 hashes as IOCs.