logo

ATTACKS OF THE LAZARUS CYBERCRIMINAL GROUP ATTENDED TO ORGANIZATIONS IN RUSSIA

ID: eb9298fd-e1d8-4d0e-8718-f14a1716bf37

STIX ID: report--eb9298fd-e1d8-4d0e-8718-f14a1716bf37

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2019-09-18

Last Modified Date: 2019-09-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report documents a Lazarus (Hidden Cobra) campaign against Russian organizations in which ZIP files contain a benign PDF decoy and a malicious Word document with macros; the macro downloads a VBS from Dropbox which then fetches a CAB from a remote server, extracts the KEYMARBLE RAT (backdoor) using expand.exe and executes it. The report provides the infection chain, descriptive analysis of KEYMARBLE behavior, IoCs (IPs 194.45.8.41 and 37.238.135.70 and multiple MD5/SHA256 hashes), and defensive recommendations for security teams and end users.