Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lazarus

Also known as: APT38, tracked as, HIDDEN COBRA, ZINC, Labyrinth Chollima, Guardians of Peace, Stardust Chollima, cryptocurrency exchanges, billions in subseq, Sapphire Sleet, WannaCry

Description

A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Aerospace
Government
Energy
Retail
Critical infrastructure
Gaming
Entertainment
Media
Manufacturing
Utilities
Healthcare
Information technology
Nuclear
Transportation

Targeted Countries / Regions

KP
US
IL
IT
RU
CA
UA
KR
ES
IN
AU
JP
NL

AI Analysis

· 2 weeks ago

Executive Summary

Lazarus, a sophisticated North Korean threat actor, has been utilizing a memory-only toolset to target financial and cryptocurrency organizations, leveraging advanced evasion techniques and a robust remote access trojan. This toolset enables the actor to maintain persistence and execute comprehensive RAT capabilities without leaving filesystem artifacts. The group's primary motivation appears to be financially motivated, with a focus on disrupting and exploiting the financial sector.

Goals & Targeting

The Lazarus threat actor's strategic objectives appear to be financially motivated, with a focus on targeting financial and cryptocurrency organizations. The group seeks to establish a foothold, disrupt operations, and exploit these organizations for financial gain. The typical victims of Lazarus are financial institutions, cryptocurrency exchanges, and related organizations, which are often targeted through sophisticated social engineering campaigns and exploit kits.

Enhanced Description

The targeting of financial and cryptocurrency organizations by Lazarus suggests a primary motivation that is financially driven, with the group seeking to disrupt and exploit these sectors for financial gain. The use of advanced evasion techniques and a robust RAT capabilities suggests that the group is well-resourced and highly motivated, posing a significant threat to organizations operating in these sectors.

Key Capabilities

  • Memory-only malware execution
  • Advanced evasion techniques (EDR evasion, ETW patching)
  • Environmental keying via DPAPI
  • Actor-in-the-loop payload delivery
  • Robust RAT capabilities (file operations, process management, command execution)
  • Plugin system for dynamically loading additional payloads

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1204
T1215
T1497

Software / Tooling

DPAPILoader
RemotePELoader
RemotePE
Custom RAT

Campaigns & Victims

The Lazarus threat actor has been observed conducting campaigns against financial and cryptocurrency organizations, often utilizing sophisticated social engineering campaigns and exploit kits to establish an initial foothold. The group's operational tempo is characterized by a high degree of adaptability and unpredictability, with the actor often switching between different tactics, techniques, and procedures (TTPs) to evade detection and maintain access to compromised systems. Notable past operations have included the targeting of cryptocurrency exchanges and financial institutions, resulting in significant financial losses.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Memory-only malware execution

Recommended Actions

  • Implement robust email filtering and social engineering training
  • Utilize advanced threat detection and response tools
  • Conduct regular vulnerability assessments and patching
  • Implement a robust incident response plan
  • Utilize a defense-in-depth approach to security

Suggested Tags

APT
Financially motivated
Cryptocurrency
North Korea

Confidence Assessment

The available data suggests a high degree of confidence in the capabilities and motivations of the Lazarus threat actor. However, there are some gaps in the available data, including the lack of specific information on the actor's command-and-control infrastructure and the full extent of their capabilities. Further research and analysis are necessary to fully understand the scope and scale of the Lazarus threat.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.huntress.com — Cited by web research for: HIDDEN COBRA
  2. attack.mitre.org — Cited by web research for: T1082
  3. blog.talosintelligence.com — Cited by web research for: T1003
  4. www.group-ib.com — Cited by web research for: T1219
  5. www.welivesecurity.com — Cited by web research for: ScoringMathTea
  6. attack.mitre.org — Cited by web research for: United States

Intel Summary

40

Techniques

43

Tools

0

Campaigns

174

IOCs

0

Observed Data

13

Tactics

Tags

Financial Targeting
Backdoor / C2

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
55%
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.