Lazarus_Group__2019__Mac_Backdoor_Linked_to_Lazarus_Targets_Korean_Users.pdf
ID: c86996e6-7ad7-45e3-909a-7bb55511b307
STIX ID: report--c86996e6-7ad7-45e3-909a-7bb55511b307
Threat Score
78/100
Uploaded: 2026-08-15
Published Date: 2019-11-21
Last Modified Date: 2019-11-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro analysis identifies a Lazarus-linked Mac backdoor campaign using a macro-embedded Excel to lure Korean users and a decoy Album.app bundle (masquerading as Flash Player) that drops a hidden backdoor at ~/.FlashUpdateCheck and a LaunchAgents plist for persistence; the backdoor implements C2 communications with multiple domains and supports commands for host info, remote shell execution, file upload/download and configuration updates, with IoCs (file names and SHA256 hashes) provided.
