Lazarus’ False Flag Malware
ID: d1a479c1-8655-467e-b34c-eed0982d8899
STIX ID: report--d1a479c1-8655-467e-b34c-eed0982d8899
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2017-02-23
Last Modified Date: 2017-02-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes a sophisticated, multi-stage watering-hole campaign attributed to the Lazarus group that targeted Polish financial institutions; it describes exploited Flash/Silverlight components (cambio.swf), multi-stage shellcode delivery, backdoor binaries (fdsvc/fdsvc.dll, srsservice.*), C2 protocol details, transliterated Russian decoy strings (false flags), and provides MD5s, filenames and URL patterns as IOCs to aid detection and mitigation.
