Lazarus
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:17
- Modified
- 29/05/2026 12:20
- Updated at
- 29/05/2026 12:20
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 11 reports, 115 attack patterns (mitre), 51 malware, 17 sectors, 13 countries, 100 indicators, 4 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (11)
-
20 MITREs 6 Malwares 10 Observables 1 APT
-
12 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
24 MITREs 1 APT
-
16 MITREs 2 Malwares 18 Observables 1 APT
-
13 MITREs 5 Malwares 1 APT
-
14 MITREs 2 Malwares 86 Observables 1 APT
-
8 MITREs 1 Malware 1 APT
-
2 CVEs 16 MITREs 8 Malwares 1 Observable 1 APT
-
1 CVE 12 MITREs 1 Malware 2 Observables 1 APT
Attack patterns (MITRE) (115)
-
T1204.001 usesMalicious Link MITRE
-
T1204 usesUser Execution MITRE
-
T1012 usesQuery Registry MITRE
-
T1543.001 usesLaunch Agent MITRE
-
T1574.002 uses
-
T1106 usesNative API MITRE
-
T1134 usesAccess Token Manipulation MITRE
-
T1055 usesProcess Injection MITRE
-
T1095 usesNon-Application Layer Protocol MITRE
-
T1543 usesCreate or Modify System Process MITRE
-
T1021.001 usesRemote Desktop Protocol MITRE
-
T1129 usesShared Modules MITRE
Malware (51)
-
Agent Tesla usesFamily
-
COPPERHEDGE usesFamily
-
QuiteRAT uses
-
Trojan:Win32/Nukesped uses
-
Charamel Loader usesFamily
-
MISTPEN usesFamily
-
JuicyPotato usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Comebacker usesFamily
-
DeimosC2 uses
-
DPAPILoader usesFamily
-
PondRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LazarLoader usesFamily
Sectors (17)
-
Universities targets
-
Road transport targets
-
Gas targets
-
Government targets
-
Nuclear power (civilian use) targets
-
Chemical targets
-
Diplomacy targets
-
Telecommunications targets
-
Healthcare targets
-
Defense ministries (including the military) targets
-
Finance targets
-
Technology targets
Countries (13)
-
Taiwan targets
-
Italy targets
-
Hong Kong targets
-
Germany targets
-
Korea, Democratic People's Republic of targets
-
Cyprus targets
-
France targets
-
Belgium targets
-
Spain targets
-
United States of America targets
-
Brazil targets
-
Japan targets
Indicators (100)
-
stix 100/100 Revoked· Valid until 13/12/2023 · Source: AlienVault
-
https://www.scgestor.com.br/wp-content/themes/vantage/inc/template-headers.phprelated -
c1029545715e5a2e433fcb4c53cdbd12b019deaf4d1f7d03be3ee680fa007219related -
https://www.bcdm.or.kr/board/type3_D/edit.asprelated -
bb1b6865e62e6149ce7f849728fcbefa27358ceb9baaa53b8089c3fb9fb56ab3related -
www.mnmathleague.orgrelated -
www.sinae.or.krrelated -
a2d3c41e6812044573a939a51a22d659ec32aea00c26c1a2fdf7466f5c7e1ee9related -
https://www.shipshorejob.com/ckeditor/samples/samples.phprelated -
toptalentassess.comrelated -
stix 100/100 Revoked· Valid until 15/09/2025 · Source: AlienVault
-
9b03695ca0945995ec6e2bc31662c08b0f499998dcbcd51701bf03add19f1000related
Vulnerabilities (CVE) (4)
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via …
- Attack vector
- Network
- Published
- 20/05/2024
- Modified
- 29/05/2026
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
- Published
- 31/03/2022
- Modified
- 29/05/2026