logo

Lazarus_Group__2017__Kaspersky_Lazarus-Under-The-Hood-PDF_final_04-03-2017.pdf

ID: d8016d76-6193-457d-be0b-cbaac5e86e27

STIX ID: report--d8016d76-6193-457d-be0b-cbaac5e86e27

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2017-04-05

Last Modified Date: 2017-04-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Kaspersky Lab intelligence report analyzes Lazarus Group and its Bluenoroff financial sub-unit, documenting multiple incidents (including the Bangladesh SWIFT heist linkage and subsequent bank intrusions in South-East Asia and Europe). The report provides forensic timelines, detailed reverse engineering of modular malware used to target SWIFT infrastructure (harvesters, patchers, backdoors, tunnel tools, keyloggers, injectors), IoCs (file hashes and C2 domains), observed anti-forensic techniques and persistence mechanisms, and recommendations for multi-layered defenses.