216.73.216.6

Lazarus APT updates its toolset in watering hole attacks

· Published 24/04/2025 08:13 · Modified 24/04/2025 13:41

Export JSON

Essential information

Published
24/04/2025 08:13
Modified
24/04/2025 13:41
Tags
2025-04-24 agamemnon downloader apt copperhedge signbt south korea supply-chain threatneedle vulnerability exploitation wagent watering hole
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 5 malware, 4 others

Description

The Lazarus group has launched a sophisticated attack campaign dubbed 'Operation SyncHole' targeting South Korean organizations. The operation combines attacks with exploitation of vulnerabilities in South Korean software. At least six organizations in the software, IT, financial, semiconductor manufacturing, and telecommunications industries were compromised. The attackers utilized updated versions of known Lazarus malware tools, including , , and . They also exploited vulnerabilities in Cross EX and Innorix Agent software for initial access and lateral movement. The campaign demonstrates Lazarus' ongoing focus on supply chain attacks targeting South Korean entities and their deep understanding of the local software ecosystem.

External references