ATTACKS OF THE LAZARUS CYBERCRIMINAL GROUP ATTENDED TO ORGANIZATIONS IN RUSSIA
ID: eb9298fd-e1d8-4d0e-8718-f14a1716bf37
STIX ID: report--eb9298fd-e1d8-4d0e-8718-f14a1716bf37
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2019-09-18
Last Modified Date: 2019-09-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report documents a Lazarus (Hidden Cobra) campaign against Russian organizations in which ZIP files contain a benign PDF decoy and a malicious Word document with macros; the macro downloads a VBS from Dropbox which then fetches a CAB from a remote server, extracts the KEYMARBLE RAT (backdoor) using expand.exe and executes it. The report provides the infection chain, descriptive analysis of KEYMARBLE behavior, IoCs (IPs 194.45.8.41 and 37.238.135.70 and multiple MD5/SHA256 hashes), and defensive recommendations for security teams and end users.
