Lazarus_Group__2019__Is_Lazarus_APT38_Targeting_Critical_Infrastructures_Marco_Ramilli_Web_Corner.pdf
ID: f018573c-1a47-49b1-8afc-a1b1e397cb6d
STIX ID: report--f018573c-1a47-49b1-8afc-a1b1e397cb6d
Threat Score
78/100
Uploaded: 2026-08-15
Published Date: 2019-12-17
Last Modified Date: 2019-12-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes a Windows PE sample tied to a claimed cyber incident at Kudankulam Nuclear Power Plant (KKNPP): it documents modular information-stealing behavior (network info, task listing, browser histories), local collection into a structured folder per host, compression and exfiltration to 10.38.1.35, hard-coded credentials and multiple file hashes, provides a YARA rule and IoCs, and argues similarities to DTrack and Lazarus/APT38 while cautioning that attribution is not definitive.
