Lazarus Group Expands Attack Approaches

In a seemingly sharp increase in activity, Lazarus group, the alias for APT38 and widely attributed to be a North Korean nation-state threat actor has doubled down on Crypto theft, going after crypto.com to acquire funds. However the most recent activity points to spear phishing attacks using Microsoft documents and piggy backs on legitimate windows update mechanisms. The target for the command and control activity is a GitHub repository, which again may be difficult to spot from legitimate traffic on your proxy.

This website stores cookies on your computer. These cookies are used to provide a more personalized experience and to track your whereabouts around our website in compliance with the European General Data Protection Regulation. If you decide to to opt-out of any future tracking, a cookie will be setup in your browser to remember this choice for one year.

Accept or Deny