logo

Lazarus_Group__2023__Kaspersky_cascade-of-compromise-unveiling-Lazarus-new-campaign_10-27-2023.pdf

ID: f11c7fff-5ad6-4ea6-807a-d8f17316c00d

STIX ID: report--f11c7fff-5ad6-4ea6-807a-d8f17316c00d

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2023-12-12

Last Modified Date: 2023-12-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky describes a multi-wave Lazarus campaign that compromised software vendors via known/unpatched vulnerabilities to distribute SIGNBT (a memory-resident loader/backdoor) and LPEClient (victim profiling and in-memory payload delivery). The report details infection chains (phantom DLL hijacking and DLL side‑loading), SIGNBT C2 protocol and commands, deployment of additional in-memory tools and credential dumpers, MITRE ATT&CK mappings, and a comprehensive set of IOCs (file hashes, file paths, and C2 URLs) for detection and response.