kaspersky-ics-cert-lazarus-targets-defense-industry-with-threatneedle-en-20210225.pdf
ID: bc56ec12-0749-414e-9d82-e0eac7b015ac
STIX ID: report--bc56ec12-0749-414e-9d82-e0eac7b015ac
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2021-02-24
Last Modified Date: 2021-02-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky ICS CERT documents a Lazarus APT campaign (ThreatNeedle) targeting defense organizations: attackers used COVID‑19 themed spear‑phishing with malicious Word macros to deploy a multi‑stage in‑memory backdoor and loaders, harvested credentials (Responder), moved laterally via Windows admin shares and WMIC, bypassed network segmentation by compromising a Webmin‑managed router and using it as a proxy, and exfiltrated sensitive IP via custom tunneling and trojanized VNC/PSCP; the report includes IOCs, timelines, and MITRE ATT&CK mapping.
