Also known as: APT38, tracked as, HIDDEN COBRA, ZINC, Labyrinth Chollima, Guardians of Peace, Stardust Chollima, cryptocurrency exchanges, billions in subseq, Sapphire Sleet, WannaCry
A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Lazarus, a sophisticated North Korean threat actor, has been utilizing a memory-only toolset to target financial and cryptocurrency organizations, leveraging advanced evasion techniques and a robust remote access trojan. This toolset enables the actor to maintain persistence and execute comprehensive RAT capabilities without leaving filesystem artifacts. The group's primary motivation appears to be financially motivated, with a focus on disrupting and exploiting the financial sector.
Goals & Targeting
The Lazarus threat actor's strategic objectives appear to be financially motivated, with a focus on targeting financial and cryptocurrency organizations. The group seeks to establish a foothold, disrupt operations, and exploit these organizations for financial gain. The typical victims of Lazarus are financial institutions, cryptocurrency exchanges, and related organizations, which are often targeted through sophisticated social engineering campaigns and exploit kits.
Enhanced Description
The targeting of financial and cryptocurrency organizations by Lazarus suggests a primary motivation that is financially driven, with the group seeking to disrupt and exploit these sectors for financial gain. The use of advanced evasion techniques and a robust RAT capabilities suggests that the group is well-resourced and highly motivated, posing a significant threat to organizations operating in these sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Lazarus threat actor has been observed conducting campaigns against financial and cryptocurrency organizations, often utilizing sophisticated social engineering campaigns and exploit kits to establish an initial foothold. The group's operational tempo is characterized by a high degree of adaptability and unpredictability, with the actor often switching between different tactics, techniques, and procedures (TTPs) to evade detection and maintain access to compromised systems. Notable past operations have included the targeting of cryptocurrency exchanges and financial institutions, resulting in significant financial losses.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data suggests a high degree of confidence in the capabilities and motivations of the Lazarus threat actor. However, there are some gaps in the available data, including the lack of specific information on the actor's command-and-control infrastructure and the full extent of their capabilities. Further research and analysis are necessary to fully understand the scope and scale of the Lazarus threat.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
43
Tools
0
Campaigns
174
IOCs
0
Observed Data
13
Tactics