BAE Systems Threat Research Blog: Lazarus’ False Flag Malware
ID: cba57c42-710b-4262-8c89-20f649b1c3de
STIX ID: report--cba57c42-710b-4262-8c89-20f649b1c3de
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2017-02-28
Last Modified Date: 2017-02-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BAE Systems Threat Research documents a sophisticated, multi‑stage watering‑hole campaign attributed to the Lazarus group that targeted financial institutions (notably Polish banks) by chaining JBoss site compromise, profiling JavaScript, and serving Flash/Silverlight exploits which load staged shellcode and ultimately deploy backdoors; the analysis includes reverse engineering of binaries, C2 protocol and keys, transliterated Russian false‑flag artifacts, and a set of IOCs (MD5 hashes, filenames, URLs).
