Lazarus_Group__2013__Dark_Seoul_Cyberattack.pdf
ID: f8e71ed1-872c-484b-97af-b25d753313e9
STIX ID: report--f8e71ed1-872c-484b-97af-b25d753313e9
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2013-06-28
Last Modified Date: 2013-06-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This paper analyzes the March 20, 2013 "Dark Seoul" attack that disrupted major South Korean banks and broadcasters, outlining a kill-chain from spearphishing and a compromised legitimate website to exploitation of CVE-2012-1889, deployment of backdoors and an infostealer, DNS poisoning to harvest credentials, and the Jokra wiper that overwrote MBRs and disks on thousands of machines; the authors conclude the operation caused high impact at large scale (>48,000 infected) despite being low in technical sophistication compared with known APT campaigns.
