Lazarus
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:17
- Modified
- 29/05/2026 12:20
- Updated at
- 29/05/2026 12:20
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 11 reports, 115 attack patterns (mitre), 51 malware, 17 sectors, 13 countries, 100 indicators, 4 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (11)
-
20 MITREs 6 Malwares 10 Observables 1 APT
-
12 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
24 MITREs 1 APT
-
16 MITREs 2 Malwares 18 Observables 1 APT
-
13 MITREs 5 Malwares 1 APT
-
14 MITREs 2 Malwares 86 Observables 1 APT
-
8 MITREs 1 Malware 1 APT
-
2 CVEs 16 MITREs 8 Malwares 1 Observable 1 APT
-
1 CVE 12 MITREs 1 Malware 2 Observables 1 APT
Attack patterns (MITRE) (115)
-
T1573.001 usesSymmetric Cryptography MITRE
-
TA0043 uses
-
T1059.001 usesPowerShell MITRE
-
T1564 usesHide Artifacts MITRE
-
T1087 usesAccount Discovery MITRE
-
T1064 usesScripting MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
Multi-Stage Channels usesT1104 MITRE
-
T1588.001 usesMalware MITRE
-
T1562.001 usesDisable or Modify Tools MITRE
-
T1203 usesExploitation for Client Execution MITRE
-
T1136 usesCreate Account MITRE
Malware (51)
-
Agent Tesla usesFamily The MITRE Corporation Confidence 100
[Agent Tesla](https://attack.mitre.org/software/S0331) is a spyware Trojan written for the .NET framework that has been observed since at least 2014.(Citation: Fortinet Agent Tesla April 2018)(Citation: Bitdefender Agent Tesla April…
First seen 01/01/1970 · Last seen 16/11/5138 · -
COPPERHEDGE usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
QuiteRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Charamel Loader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
MISTPEN usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
JuicyPotato usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Comebacker usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DeimosC2 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DPAPILoader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PondRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LazarLoader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (17)
-
Universities targets
-
Road transport targets
-
Gas targets
-
Government targets
-
Nuclear power (civilian use) targets
-
Chemical targets
-
Diplomacy targets
-
Telecommunications targets
-
Healthcare targets
-
Defense ministries (including the military) targets
-
Finance targets
-
Technology targets
Countries (13)
-
Taiwan targets
-
Italy targets
-
Hong Kong targets
-
Germany targets
-
Korea, Democratic People's Republic of targets
-
Cyprus targets
-
France targets
-
Belgium targets
-
Spain targets
-
United States of America targets
-
Brazil targets
-
Japan targets
Indicators (100)
-
stix 100/100 Revoked· Valid until 13/12/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 20/11/2022 · Source: AlienVault
-
stix 100/100· Valid until 30/08/2026 · Source: AlienVault
-
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of e7aa0237fc3db67a96ebd877806a2c88
· Valid until 15/07/2024 · Source: AlienVault -
9dddf5a1d32e3ba7cc27f1006a843bfd4bc34fa8a149bcc522f27bda8e95db14related -
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of 880b263b4fd5de0ae6224189ea611023
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100· Valid until 21/05/2027 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 28/03/2026 · Source: AlienVault
Vulnerabilities (CVE) (4)
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via …
- Attack vector
- Network
- Published
- 20/05/2024
- Modified
- 29/05/2026
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
- Published
- 31/03/2022
- Modified
- 29/05/2026