logo

kaspersky-ics-cert-lazarus-targets-defense-industry-with-threatneedle-en-20210225.pdf

ID: bc56ec12-0749-414e-9d82-e0eac7b015ac

STIX ID: report--bc56ec12-0749-414e-9d82-e0eac7b015ac

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2021-02-24

Last Modified Date: 2021-02-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky ICS CERT documents a Lazarus APT campaign (ThreatNeedle) targeting defense organizations: attackers used COVID‑19 themed spear‑phishing with malicious Word macros to deploy a multi‑stage in‑memory backdoor and loaders, harvested credentials (Responder), moved laterally via Windows admin shares and WMIC, bypassed network segmentation by compromising a Webmin‑managed router and using it as a proxy, and exfiltrated sensitive IP via custom tunneling and trojanized VNC/PSCP; the report includes IOCs, timelines, and MITRE ATT&CK mapping.