Lazarus_Group__2020__Weaponizing_a_Lazarus_Group_Implant.pdf
ID: ce566487-a765-4cf2-ac79-59f6c33d4137
STIX ID: report--ce566487-a765-4cf2-ac79-59f6c33d4137
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2020-02-27
Last Modified Date: 2020-02-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Objective-See's blog analyzes a Lazarus Group macOS 1st-stage loader (unioncryptoupdater/macloader), reverse-engineers its network protocol and payload format (base64-encoded, AES-CBC with null IV and key MD5("VMI5E0hq8gDz"), payload at offset 0x90, minimum 0x400 bytes), and demonstrates how to repurpose the loader by changing its hardcoded C2 to deliver and execute custom Mach-O payloads directly from memory; the post also documents persistence paths (/Library/LaunchDaemons/vip.unioncrypto.plist, /Library/UnionCrypto/unioncryptoupdater), C2 URL (https://unioncrypto.vip/update), detection considerations, and limitations of macOS memory forensics.
