logo

BAE Systems Threat Research Blog: Lazarus’ False Flag Malware

ID: cba57c42-710b-4262-8c89-20f649b1c3de

STIX ID: report--cba57c42-710b-4262-8c89-20f649b1c3de

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2017-02-28

Last Modified Date: 2017-02-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BAE Systems Threat Research documents a sophisticated, multi‑stage watering‑hole campaign attributed to the Lazarus group that targeted financial institutions (notably Polish banks) by chaining JBoss site compromise, profiling JavaScript, and serving Flash/Silverlight exploits which load staged shellcode and ultimately deploy backdoors; the analysis includes reverse engineering of binaries, C2 protocol and keys, transliterated Russian false‑flag artifacts, and a set of IOCs (MD5 hashes, filenames, URLs).