Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Follow the Clues: Everyday is lazarus.day
Search
JeongGak Lyu
January 21, 2025
Technology
21
0
Share
Follow the Clues: Everyday is lazarus.day
This talk was presented at JSAC 2025.
JeongGak Lyu
January 21, 2025
More Decks by JeongGak Lyu
See All by JeongGak Lyu
Exploiting Trust: When a Trusted Security Solution Becomes a DPRK Trojan Horse
jglyu
0
10
공격자의 시선에서 바라본 금융보안: 사이버 복원력 강화를 위한 레드티밍 전략
jglyu
0
41
금융분야 침해사고 동향 및 시사점
jglyu
0
19
He is everywhere: A tale of Lazarus and his family
jglyu
0
42
Other Decks in Technology
See All in Technology
プラットフォームエンジニア ワークショップ/ platform-workshop
databricksjapan
0
110
オンコールの負荷軽減のためのBits Assistant 活用方法 / How to Use Bits Assistant to Reduce the Workload on On-Call Staff
sms_tech
1
300
類似画像検索モデルの開発ノウハウ
lycorptech_jp
PRO
4
1k
テストコードのないプロジェクトにテストを根付かせる
tttol
0
220
Fabric-cicd によるAzure DevOps デプロイ
ryomaru0825
0
110
Datadog 認定試験の概要と対策
uechishingo
0
150
Oracle Cloud Infrastructure:2026年5月度サービス・アップデート
oracle4engineer
PRO
1
230
Kiro CLI v2.0.0がやってきた!
kentapapa
0
210
食べログのサーキットブレーカー導入を振り返って
atpons
1
150
管理アカウント単一運用からAWS Organizationsに移行するの大変で滅
hiramax
0
300
Anthropic AIネイティブ・スタートアップ構築のプレイブック を理解する
nagatsu
0
210
インフラが苦手でも大丈夫! 紙芝居 Kubernetes -WWGT 10周年編-
aoi1
1
300
Featured
See All Featured
Optimizing for Happiness
mojombo
378
71k
The World Runs on Bad Software
bkeepers
PRO
72
12k
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
31
10k
Leo the Paperboy
mayatellez
7
1.8k
Neural Spatial Audio Processing for Sound Field Analysis and Control
skoyamalab
0
310
The Straight Up "How To Draw Better" Workshop
denniskardys
239
140k
How to Grow Your eCommerce with AI & Automation
katarinadahlin
PRO
1
190
How to Think Like a Performance Engineer
csswizardry
28
2.6k
The Impact of AI in SEO - AI Overviews June 2024 Edition
aleyda
5
1.1k
Navigating Algorithm Shifts & AI Overviews - #SMXNext
aleyda
1
1.2k
Deep Space Network (abreviated)
tonyrice
0
150
VelocityConf: Rendering Performance Case Studies
addyosmani
333
25k
Transcript
2025-01-21 JeongGak Lyu @lazarusholic Follow the Clues Everyday is lazarus.day
The Evolving Threat Landscape Political or Social Agendas Financial Gain
Political Influence and Espionage DPRK State-Sponsored Threat Actors
Cyber Threat Intelligence Essentials The Pyramid of Pain CTI Lifecycle
Data Information Intelligence https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html https://www.gartner.com/document-reader/document/4056399
Threat Detection & Threat Hunting Proactive Approach Targets Unknown Threats
Searching for Evil Reactive Approach Focus on Known Threats Detecting Evil Rely on CTI & IOCs Mitigating Threats
Inside a CTI Report CTI Report Collections & Platforms •
DocIntel https://docintel.org/ • ioc[.]one https://ioc.one/ • Malpedia https://malpedia.caad.fkie.fraunhofer.de/ • ORKL https://orkl.eu/ • Threat Intelligence Reports https://mthcht.github.io/ThreatIntel-Reports/ • Vx Underground https://vx-underground.org/ Each Item can be a Clue
IOC Pivoting / Enrichment
IOC Pivoting with OSINT
Introduction to lazarus.day Reports 2,470 Actors 187 Incidents 187 Kimsuky
Lazarus ScarCruft Andariel Konni BlueNoroff DPRK FamousChollima
Everyday is lazarus.day cryptocopedia[.]com
Strategies for Enhanced Threat Intelligence Set Clear Goals! Automation, Automation,
Automation! Adopt Generative AI! Tools to Spark Ideas • Harpoon https://github.com/Te-k/harpoon • IntelOwl https://intelowlproject.github.io/ • Censeye https://github.com/Censys-Research/censeye • SecAI https://secai.ai/ • TI Mindmap https://github.com/format81/TI-Mindmap-GPT CTI Lifecycle
Conclusion • Following the Clues is an Endless Journey -
Requires Patience, Expertise and Investment • Maximize the Use of OSINT • Evaluate Your CTI Capability Maturity CTI Capability Maturity Model https://cti-cmm.org/ Asset Threat Risk Access Situation Response Thrid-Parties Fraud Workforce Architecture Program 0 25 50 75 100
Background Images: Unsplash Marek Piwnicki @lazarusholic https://lazarus.day Q & A