Lazarus
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:17
- Modified
- 29/05/2026 12:20
- Updated at
- 29/05/2026 12:20
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 11 reports, 115 attack patterns (mitre), 51 malware, 17 sectors, 13 countries, 100 indicators, 4 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (11)
-
20 MITREs 6 Malwares 10 Observables 1 APT
-
12 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
14 MITREs 3 Malwares 1 APT
-
24 MITREs 1 APT
-
16 MITREs 2 Malwares 18 Observables 1 APT
-
13 MITREs 5 Malwares 1 APT
-
14 MITREs 2 Malwares 86 Observables 1 APT
-
8 MITREs 1 Malware 1 APT
-
2 CVEs 16 MITREs 8 Malwares 1 Observable 1 APT
-
1 CVE 12 MITREs 1 Malware 2 Observables 1 APT
Attack patterns (MITRE) (115)
-
T1204.001 usesMalicious Link MITRE
-
T1204 usesUser Execution MITRE
-
T1012 usesQuery Registry MITRE
-
T1543.001 usesLaunch Agent MITRE
-
T1574.002 uses
-
T1106 usesNative API MITRE
-
T1134 usesAccess Token Manipulation MITRE
-
T1055 usesProcess Injection MITRE
-
T1095 usesNon-Application Layer Protocol MITRE
-
T1543 usesCreate or Modify System Process MITRE
-
T1021.001 usesRemote Desktop Protocol MITRE
-
T1129 usesShared Modules MITRE
Malware (51)
-
Agent Tesla usesFamily
-
COPPERHEDGE usesFamily
-
QuiteRAT uses
-
Trojan:Win32/Nukesped uses
-
Charamel Loader usesFamily
-
MISTPEN usesFamily
-
JuicyPotato usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Comebacker usesFamily
-
DeimosC2 uses
-
DPAPILoader usesFamily
-
PondRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LazarLoader usesFamily
Sectors (17)
-
Universities targets
-
Road transport targets
-
Gas targets
-
Government targets
-
Nuclear power (civilian use) targets
-
Chemical targets
-
Diplomacy targets
-
Telecommunications targets
-
Healthcare targets
-
Defense ministries (including the military) targets
-
Finance targets
-
Technology targets
Countries (13)
-
Taiwan targets
-
Italy targets
-
Hong Kong targets
-
Germany targets
-
Korea, Democratic People's Republic of targets
-
Cyprus targets
-
France targets
-
Belgium targets
-
Spain targets
-
United States of America targets
-
Brazil targets
-
Japan targets
Indicators (100)
-
crm.vncgroup.comrelated -
37a3c01bb5eaf7ecbcfbfde1aab848956d782bb84445384c961edebe8d0e9969related -
blockchainjobassessment.comrelatedstix 100/100 Revoked· Valid until 27/08/2025 · Source: AlienVault -
apdl.cfrelated -
www.rsdf.krrelated -
connection.lockscreen.kro.krrelated -
919dfa31f284412d41e45a90520de2bacd211e7ad92d68512108f1302385c79frelated -
stix 100/100 Revoked· Valid until 13/12/2023 · Source: AlienVault
-
fb1e0719a35635aa882fe5545d154f2d4349277e6a9ff89a29f1af229e29b034related -
e4ce73b4dbbd360a17f482abcae2d479bc95ea546d67ec257785fa51872b2e3frelated
Vulnerabilities (CVE) (4)
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via …
- Attack vector
- Network
- Published
- 20/05/2024
- Modified
- 29/05/2026
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.
- Published
- 31/03/2022
- Modified
- 29/05/2026