logo

Lazarus_Group__2019__Mac_Backdoor_Linked_to_Lazarus_Targets_Korean_Users.pdf

ID: c86996e6-7ad7-45e3-909a-7bb55511b307

STIX ID: report--c86996e6-7ad7-45e3-909a-7bb55511b307

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2019-11-21

Last Modified Date: 2019-11-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro analysis identifies a Lazarus-linked Mac backdoor campaign using a macro-embedded Excel to lure Korean users and a decoy Album.app bundle (masquerading as Flash Player) that drops a hidden backdoor at ~/.FlashUpdateCheck and a LaunchAgents plist for persistence; the backdoor implements C2 communications with multiple domains and supports commands for host info, remote shell execution, file upload/download and configuration updates, with IoCs (file names and SHA256 hashes) provided.