216.73.217.98

Analysis of APT-C-26 (Lazarus) Group's Attack Campaign Using Remote IT Disguise to Deploy Monitoring Software

· Published 21/11/2025 22:11 · Modified 21/11/2025 22:36

Export JSON

Essential information

Published
21/11/2025 22:11
Modified
21/11/2025 22:36
Tags
2025-11-21 apt monitoring software monitorinstaller_update1.exe north korea persistence remote desktop remote it screen capture systemuiext.dll winupdateservice.exe
Related entities
1 intrusion sets (apt), 5 others

Description

The report details an attack campaign by -C-26 (Lazarus), a highly active group targeting various industries globally. The group deployed a customized monitoring program with control capabilities, likely used by personnel infiltrating target companies. The malware consists of a registration program, a daemon process, and a DLL file for core monitoring functions. It utilizes Windows Shell extension for and creates a covert environment. The analysis reveals sophisticated techniques for evading detection, including disabling Windows Defender and manipulating firewall rules. The captures screen data, uploads it to a server, and provides functionality. Based on the analysis and tactics used, the activity is attributed to the Lazarus group.

External references