Lazarus_Group__2023__Kaspersky_cascade-of-compromise-unveiling-Lazarus-new-campaign_10-27-2023.pdf
ID: f11c7fff-5ad6-4ea6-807a-d8f17316c00d
STIX ID: report--f11c7fff-5ad6-4ea6-807a-d8f17316c00d
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2023-12-12
Last Modified Date: 2023-12-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky describes a multi-wave Lazarus campaign that compromised software vendors via known/unpatched vulnerabilities to distribute SIGNBT (a memory-resident loader/backdoor) and LPEClient (victim profiling and in-memory payload delivery). The report details infection chains (phantom DLL hijacking and DLL side‑loading), SIGNBT C2 protocol and commands, deployment of additional in-memory tools and credential dumpers, MITRE ATT&CK mappings, and a comprehensive set of IOCs (file hashes, file paths, and C2 URLs) for detection and response.
