Lazarus
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:17
- Modified
- 29/05/2026 12:20
- Updated at
- 29/05/2026 12:20
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 11 reports, 115 attack patterns (mitre), 51 malware, 17 sectors, 13 countries, 100 indicators, 4 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (11)
-
20 MITREs 6 Malwares 10 Observables 1 APT
-
12 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
24 MITREs 1 APT
-
16 MITREs 2 Malwares 18 Observables 1 APT
-
13 MITREs 5 Malwares 1 APT
-
14 MITREs 2 Malwares 86 Observables 1 APT
-
8 MITREs 1 Malware 1 APT
-
2 CVEs 16 MITREs 8 Malwares 1 Observable 1 APT
-
1 CVE 12 MITREs 1 Malware 2 Observables 1 APT
Attack patterns (MITRE) (115)
-
T1496 usesResource Hijacking MITRE
-
T1018 usesRemote System Discovery MITRE
-
T1566 usesPhishing MITRE
-
T1546 usesEvent Triggered Execution MITRE
-
T1583.003 usesVirtual Private Server MITRE
-
T1113 usesScreen Capture MITRE
-
T1218 usesSystem Binary Proxy Execution MITRE
-
T1495 usesFirmware Corruption MITRE
-
T1548 usesAbuse Elevation Control Mechanism MITRE
-
T1587.001 usesMalware MITRE
-
T1123 usesAudio Capture MITRE
-
T1071 usesApplication Layer Protocol MITRE
Malware (51)
-
Agent Tesla usesFamily The MITRE Corporation Confidence 100
[Agent Tesla](https://attack.mitre.org/software/S0331) is a spyware Trojan written for the .NET framework that has been observed since at least 2014.(Citation: Fortinet Agent Tesla April 2018)(Citation: Bitdefender Agent Tesla April…
First seen 01/01/1970 · Last seen 16/11/5138 · -
COPPERHEDGE usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
QuiteRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Charamel Loader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
MISTPEN usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
JuicyPotato usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Comebacker usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DeimosC2 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DPAPILoader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PondRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LazarLoader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (17)
-
Universities targets
-
Road transport targets
-
Gas targets
-
Government targets
-
Nuclear power (civilian use) targets
-
Chemical targets
-
Diplomacy targets
-
Telecommunications targets
-
Healthcare targets
-
Defense ministries (including the military) targets
-
Finance targets
-
Technology targets
Countries (13)
-
Taiwan targets
-
Italy targets
-
Hong Kong targets
-
Germany targets
-
Korea, Democratic People's Republic of targets
-
Cyprus targets
-
France targets
-
Belgium targets
-
Spain targets
-
United States of America targets
-
Brazil targets
-
Japan targets
Indicators (100)
-
stix 100/100 Revoked· Valid until 18/10/2025 · Source: AlienVault
-
https://tecnojournals.com/prestrelatedstix 100/100 RevokedHTML document, ASCII text, with CRLF, LF line terminators 5dc1ae0b875dc0d78dbc5532226f5f31b762b4d1229984f605d27bf895ab6807
· Valid until 22/08/2022 · Source: AlienVault -
stix 100/100 Revoked
Zeppelin_37 SHA256 of 84cd4d896748e2d52e2e22d1a4b9ee46
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
kernel32_dll_xor_exe_key_1 SHA256 of a966668feca72d8dddf3c737d4908a29
· Valid until 22/01/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 13/12/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 10/06/2025 · Source: AlienVault
-
stix 100/100· Valid until 01/09/2026 · Source: AlienVault
-
stix 100/100 Revoked
Armadillov1xxv2xx SHA256 of 64965a88e819fb93dbabafc4e3ad7b6c
· Valid until 18/01/2025 · Source: AlienVault -
ftp.qurvegraphics.comrelated
Vulnerabilities (CVE) (4)
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via …
- Attack vector
- Network
- Published
- 20/05/2024
- Modified
- 29/05/2026
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
- Published
- 31/03/2022
- Modified
- 29/05/2026