logo

Lazarus_Group__2020__Weaponizing_a_Lazarus_Group_Implant.pdf

ID: ce566487-a765-4cf2-ac79-59f6c33d4137

STIX ID: report--ce566487-a765-4cf2-ac79-59f6c33d4137

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2020-02-27

Last Modified Date: 2020-02-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Objective-See's blog analyzes a Lazarus Group macOS 1st-stage loader (unioncryptoupdater/macloader), reverse-engineers its network protocol and payload format (base64-encoded, AES-CBC with null IV and key MD5("VMI5E0hq8gDz"), payload at offset 0x90, minimum 0x400 bytes), and demonstrates how to repurpose the loader by changing its hardcoded C2 to deliver and execute custom Mach-O payloads directly from memory; the post also documents persistence paths (/Library/LaunchDaemons/vip.unioncrypto.plist, /Library/UnionCrypto/unioncryptoupdater), C2 URL (https://unioncrypto.vip/update), detection considerations, and limitations of macOS memory forensics.