Saini, A. and Hossein, J. (2022, January 27). North Korea’s Lazarus APT leverages Windows Update client, GitHub in latest campaign. Retrieved January 27, 2022.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.007 Dynamic API Resolution |
GroupLazarus Group | Lazarus Group has used a custom hashing method to resolve APIs used in shellcode. |
| T1027.013 Encrypted/Encoded File |
GroupLazarus Group | Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names. |
| T1033 System Owner/User Discovery |
GroupLazarus Group | Various Lazarus Group malware enumerates logged-on users. |
| T1055.001 Dynamic-link Library Injection |
GroupLazarus Group | A Lazarus Group malware sample performs reflective DLL injection. |
| T1057 Process Discovery |
GroupLazarus Group | Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times. |
| T1059.005 Visual Basic |
GroupLazarus Group | Lazarus Group has used VBA and embedded macros in Word documents to execute malicious code. |
| T1070 Indicator Removal |
GroupLazarus Group | Lazarus Group has restored malicious KernelCallbackTable code to its original state after the process execution flow has been hijacked. |
| T1071.001 Web Protocols |
GroupLazarus Group | Lazarus Group has conducted C2 over HTTP and HTTPS. |
| T1082 System Information Discovery |
GroupLazarus Group | Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information. |
| T1083 File and Directory Discovery |
GroupLazarus Group | Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives. |
| T1102.002 Bidirectional Communication |
GroupLazarus Group | Lazarus Group has used GitHub as C2, pulling hosted image payloads then committing command execution output to files in specific directories. |
| T1104 Multi-Stage Channels |
GroupLazarus Group | Lazarus Group has used multi-stage malware components that inject later stages into separate processes. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1106 Native API |
GroupLazarus Group | Lazarus Group has used the Windows API |
| T1140 Deobfuscate/Decode Files or Information |
GroupLazarus Group | Lazarus Group has used shellcode within macros to decrypt and manually map DLLs and shellcode into memory at runtime. |
| T1204.002 Malicious File |
GroupLazarus Group | Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email. |
| T1218 System Binary Proxy Execution |
GroupLazarus Group | Lazarus Group lnk files used for persistence have abused the Windows Update Client ( |
| T1218.005 Mshta |
GroupLazarus Group | Lazarus Group has used |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLazarus Group | Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key. |
| T1553.002 Code Signing |
GroupLazarus Group | Lazarus Group has digitally signed malware and utilities to evade detection. |
| T1564.001 Hidden Files and Directories |
GroupLazarus Group | Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application. |
| T1566.001 Spearphishing Attachment |
GroupLazarus Group | Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents. |
| T1574.013 KernelCallbackTable |
GroupLazarus Group | Lazarus Group has abused the |
| T1620 Reflective Code Loading |
GroupLazarus Group | Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime. |
| T1680 Local Storage Discovery |
GroupLazarus Group | A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.