Lazarus
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:17
- Modified
- 29/05/2026 12:20
- Updated at
- 29/05/2026 12:20
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 11 reports, 115 attack patterns (mitre), 51 malware, 17 sectors, 13 countries, 100 indicators, 4 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (11)
-
20 MITREs 6 Malwares 10 Observables 1 APT
-
12 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
24 MITREs 1 APT
-
16 MITREs 2 Malwares 18 Observables 1 APT
-
13 MITREs 5 Malwares 1 APT
-
14 MITREs 2 Malwares 86 Observables 1 APT
-
8 MITREs 1 Malware 1 APT
-
2 CVEs 16 MITREs 8 Malwares 1 Observable 1 APT
-
1 CVE 12 MITREs 1 Malware 2 Observables 1 APT
Attack patterns (MITRE) (115)
-
T1584.001 usesDomains MITRE
-
T1543.003 usesWindows Service MITRE
-
T1134.002 usesCreate Process with Token MITRE
-
T1562 usesImpair Defenses MITRE
-
T1068 usesExploitation for Privilege Escalation MITRE
-
T1569.002 usesService Execution MITRE
-
T1125 usesVideo Capture MITRE
-
T1547 usesBoot or Logon Autostart Execution MITRE
-
T1056 usesInput Capture MITRE
-
T1608.001 usesUpload Malware MITRE
-
T1074 usesData Staged MITRE
-
T1049 usesSystem Network Connections Discovery MITRE
Malware (51)
-
CollectionRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ScoringMathTea usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
RollMid usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Operation DreamJob usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Lazarus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
pycryptoenv usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
POOLRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Linux MATA usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AppleJeus usesFamily The MITRE Corporation Confidence 100
[AppleJeus](https://attack.mitre.org/software/S0584) is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications. [AppleJeus](https://attack.mitre.org/software/S0584) has been used by [Lazarus Group](https://attack.mitre.org/groups/G0032), targeting companies in the energy, finance,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
ServiceChanger usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Volgmer usesFamily The MITRE Corporation Confidence 100
[Volgmer](https://attack.mitre.org/software/S0180) is a backdoor Trojan designed to provide covert access to a compromised system. It has been used since at least 2013 to target the government, financial, automotive,…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (17)
-
Universities targets
-
Road transport targets
-
Gas targets
-
Government targets
-
Nuclear power (civilian use) targets
-
Chemical targets
-
Diplomacy targets
-
Telecommunications targets
-
Healthcare targets
-
Defense ministries (including the military) targets
-
Finance targets
-
Technology targets
Countries (13)
-
Taiwan targets
-
Italy targets
-
Hong Kong targets
-
Germany targets
-
Korea, Democratic People's Republic of targets
-
Cyprus targets
-
France targets
-
Belgium targets
-
Spain targets
-
United States of America targets
-
Brazil targets
-
Japan targets
Indicators (100)
-
stix 100/100 Revoked· Valid until 13/12/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 09/12/2025 · Source: AlienVault
-
stix 100/100 Revoked
LZMA SHA256 of e9d89d1364bd73327e266d673d6c8acf
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked· Valid until 05/08/2023 · Source: AlienVault
-
stix 100/100 Revoked
LZMA SHA256 of 075fba0c098d86d9f22b8ea8c3033207
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked· Valid until 06/03/2024 · Source: AlienVault
-
stix 100/100 Revoked
HTML document, ASCII text, with very long lines 3d70ce95eb1eb78620cc57fe1a6a479e6f2d70508bf813238e573863df000d6e
· Valid until 22/08/2022 · Source: AlienVault -
stix 100/100 Revoked· Valid until 15/09/2025 · Source: AlienVault
-
9b03695ca0945995ec6e2bc31662c08b0f499998dcbcd51701bf03add19f1000related
Vulnerabilities (CVE) (4)
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via …
- Attack vector
- Network
- Published
- 20/05/2024
- Modified
- 29/05/2026
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
- Published
- 31/03/2022
- Modified
- 29/05/2026