ATT&CKReferencesGoogle TAG Lazarus Jan 2021

Google TAG Lazarus Jan 2021

Weidemann, A. (2021, January 25). New campaign targeting security researchers. Retrieved December 20, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupLazarus Group

Lazarus Group has used PowerShell to execute commands and malicious code.

T1105
Ingress Tool Transfer
GroupLazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.

T1189
Drive-by Compromise
GroupLazarus Group

Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website.

T1566.003
Spearphishing via Service
GroupLazarus Group

Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages.

T1583.001
Domains
GroupLazarus Group

Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels.

T1585.001
Social Media Accounts
GroupLazarus Group

Lazarus Group has created new Twitter accounts to conduct social engineering against potential victims.

T1587.001
Malware
GroupLazarus Group

Lazarus Group has developed custom malware for use in their operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.