logo

Lazarus’ False Flag Malware

ID: d1a479c1-8655-467e-b34c-eed0982d8899

STIX ID: report--d1a479c1-8655-467e-b34c-eed0982d8899

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2017-02-23

Last Modified Date: 2017-02-23

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes a sophisticated, multi-stage watering-hole campaign attributed to the Lazarus group that targeted Polish financial institutions; it describes exploited Flash/Silverlight components (cambio.swf), multi-stage shellcode delivery, backdoor binaries (fdsvc/fdsvc.dll, srsservice.*), C2 protocol details, transliterated Russian decoy strings (false flags), and provides MD5s, filenames and URL patterns as IOCs to aid detection and mitigation.