In 2019, F-Secure uncovered technical details on Lazarus Group’s modus operandi during an investigation of an attack on an organisation in the cryptocurrency vertical. Consistent with public reporting on the group’s activities, the main objective of the attack was financial gain.
F-Secure assess the attack on the target to be advanced in nature and was able to link this activity with a global phishing campaign running since at least January 2018. The attack was linked to this wider set of activity through several common indicators found in samples from the investigation, open source repositories, and proprietary intelligence sources.
Lazarus Group’s activities are a continued threat: the phishing campaign associated with this attack has been observed continuing into 2020, raising the need for awareness and ongoing vigilance amongst organisations operating in the targeted verticals. It is F-Secure’s assessment that the group will continue to target organisations within the cryptocurrency vertical while it remains such a profitable pursuit, but may also expand to target supply chain elements of the vertical to increase returns and longevity of the campaign.
Where possible, evidence has been included in the body and appendices of this report to allow the security industry to leverage these details across their apertures, and draw their own conclusions. F-Secure believes the detail in this report will help targeted organizations protect their networks from future attacks and raise the cost of operation for the group.
What next?
Discover WithSecure™ Elements Exposure Management.
– No credit card required. No obligations.No complexity.
Related Labs content
Find related content relating to this topic.
W/Labs
DarkGate Rises: New version of DarkGate malware hunts like a Duck but bites like a RAT
On 4th August 2023, WithSecure Detection and Response Team (DRT) received an alert regarding spoofed process injection with abnormal memory characteristics on a host belonging to a WithSecure Countercept MDR customer.
W/Labs
Reverse engineering a Lumma infection
Lumma is an information stealer that the WithSecure Detection and Response Team (DRT) have encountered several times. It has seen wider use over the past couple of years, and makes for an interesting threat to monitor.
W/Labs
Machine learning-driven malware analysis
With the rapid emergence of new malware variants, accurately classifying and attributing malware samples has become more challenging than ever