Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
He is everywhere: A tale of Lazarus and his family
Search
JeongGak Lyu
October 17, 2023
Technology
43
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
He is everywhere: A tale of Lazarus and his family
This talk was presented at Hack.lu & CTI Summit 2023.
JeongGak Lyu
October 17, 2023
More Decks by JeongGak Lyu
See All by JeongGak Lyu
Exploiting Trust: When a Trusted Security Solution Becomes a DPRK Trojan Horse
jglyu
0
14
공격자의 시선에서 바라본 금융보안: 사이버 복원력 강화를 위한 레드티밍 전략
jglyu
0
42
Follow the Clues: Everyday is lazarus.day
jglyu
0
22
금융분야 침해사고 동향 및 시사점
jglyu
0
21
Other Decks in Technology
See All in Technology
AIネイティブな開発のサプライチェーンリスク対策 〜激動の開発現場でリスクに立ち向かう〜【ZennFes】
cscengineer
PRO
2
130
AI駆動開発を通して感じた、 AI時代のデザイナーの役割変化
whisaiyo
3
2.1k
気づかぬうちにセキュリティ負債を生むAPIキー運用
sgwrmctk
0
130
SONiCで構築・運用する生成AI向けパブリッククラウドネットワーク ~実装編~
sonic
0
210
2026 TECHFRESH 畢業分享會 - AI-Native 重塑軟體工程與虛擬講師
line_developers_tw
PRO
0
1.1k
なぜ Platform Engineering の土台に Kubernetes を選ぶのか
r4ynode
2
640
不要なレビューをAIにまかせて AIコーディングの環境改善を加速した
shoota
1
120
2026TECHFRESH畢業分享會 - 原生還是跨平台? App 開發踩坑實錄
line_developers_tw
PRO
0
1.1k
Disciplined Vibes: Scaling AI-Assisted Engineering
sheharyar
0
150
プロダクト開発から業務改善コンサルまで。事業全体へ「染み出す」ことで広がるエンジニアの可能性
ham0215
0
130
Android の公式 Skill / Android skills
yanzm
0
150
マルチアカウント環境での コーディングエージェントを使った障害調査が大変なので AIエージェントにReadOnly権限を付与してみた / ReadOnly AI Agents for Multi-Account AWS Incident Response
yamaguchitk333
2
110
Featured
See All Featured
XXLCSS - How to scale CSS and keep your sanity
sugarenia
250
1.3M
The untapped power of vector embeddings
frankvandijk
2
1.8k
Navigating Algorithm Shifts & AI Overviews - #SMXNext
aleyda
1
1.3k
Marketing Yourself as an Engineer | Alaka | Gurzu
gurzu
0
230
Un-Boring Meetings
codingconduct
0
310
Testing 201, or: Great Expectations
jmmastey
46
8.2k
Ecommerce SEO: The Keys for Success Now & Beyond - #SERPConf2024
aleyda
1
2k
Improving Core Web Vitals using Speculation Rules API
sergeychernyshev
21
1.5k
Groundhog Day: Seeking Process in Gaming for Health
codingconduct
0
210
Technical Leadership for Architectural Decision Making
baasie
3
410
The Hidden Cost of Media on the Web [PixelPalooza 2025]
tammyeverts
2
330
Leadership Guide Workshop - DevTernity 2021
reverentgeek
1
300
Transcript
2023-10-17, @lazarusholic JeongGak Lyu, Financial Security Institute He is everywhere
A tale of Lazarus and his family
Who are Lazarus and his family? • Behind Infamous Cyber
Incidents • Democratic People's Republic of Korea(DPRK, North Korea) stated- sponsored Threat Actors • Most Wanted Threat Actors in the World
# of posts by year
Top 10 authors "IOMBC &454FDVSJUZ ,BTQFSTLZ
/4)$ 64$*4" ,3$&35 2JIPP 4BLBJ &4&5 )BVSJ
Lazarus by the numbers Aliases (Associated Groups) 143 Posts Authors
Notable Activities 1,638 329 109 Victim Countries 57
MISP Threat Actor Galaxy https://www.misp-project.org/galaxy.html
MITRE ATT&CK Groups %13, 5ISFBU"DUPST ( -B[BSVT(SPVQ -BCZSJOUI$IPMMJNB )JEEFO$PCSB (VBSEJBOTPG1FBDF
;*/$ /JDLFM"DBEFNZ "15 ( 3JDPDIFU$IPMMJNB *OLZ4RVJE 4DBS$SVGU 3FBQFS (SPVQ 5&.13FBQFS "15 ( 4UBSEVTU$IPMMJNB #FBHMF#PZ[ #MVF/PSPGG /JDLFM(MBETUPOF ,JNTVLZ ( 7FMWFU$IPMMJNB 5IBMMJVN #MBDL#BOTIFF 4UPMFO1FODJM "OEBSJFM ( 4JMFOU$IPMMJNB https://attack.mitre.org/groups/
Mandiant ,*. 3(# 5&.1)FSNJU "15 "15 "OEBSJFM .JOJTUSZPG 4UBUVF4FDVSJUZ "15
0GGJDF 3FTFBSDI 3FTFBSDI SE#VSFBV 3(# "OEBSJFM ,JNTVLZ -B[BSVT ,*. UN Security Council https://www.mandiant.com/resources/mapping-dprk-groups-to-government https://www.mandiant.com/resources/blog/north-korea-cyber-structure-alignment-2023 https://undocs.org/Home/Mobile?FinalSymbol=S%2F2023%2F171 ,*. 3(# "OEBSJFM 5&.1)FSNJU "15 #VSFBV -BC SE#VSFBV $FSJVN ,JNTVLZ UI#VSFBV .JOJTUSZPG 4UBUVF4FDVSJUZ "15
Naming conventions: Simple • Qihoo360: APT-C-[N] • Cisco Talos: Group[N]
• Elastic: REF[N] • IBM: ITG[N], Hive[N] • Mandiant: APT[N], UNC[N] • Microsoft: Element Name(Deprecated) • NSHC: Sector[A][N] • Proofpoint: TA[N] • Recorded Future: TAG-[N] • Secureworks: CTG-[N] • Thales Group: ATK[N] • Qianxin: APT-Q-[N]
Naming conventions: State-sponsored China DPRK Iran Russia Crowd Strike Panda
Chollima Kitten Bear Microsoft Typhoon Sleet Sandstrom Blizzard NSHC SectorB SectorA SectorD SectorC Paloalto Networks Taurus Pisces Serpens Ursa PWC Red Black Yellow Blue Secureworks Bronze Nickel Cobalt Iron
Naming conventions: DPRK • Ahnlab: Red [Dot | Eyes] •
CrowdStrike: [Labyrinth | Ricochet | Silent | Startdust | Velvet] Chollima • KRCERT: Red [Carpet | Kim | Light] • Microsoft: [Citrine | Diamond | Emerald | Jade | Onyx | Opal | Pearl | Ruby | Sapphire] Sleet • NSHC: SectorA[01 - 07] • Paloalto Networks: [Crooked | Moldy | Selective] Pisces • PWC: Black [Alicanto | Artemis | Banshee | Dev2 | Shoggoth] • Secureworks: Nickel [Academy | Foxcroft | Hyatt | Kimball]
Lazarus, and his family #MVF/PSPGG ,JNTVLZ "OEBSJFM ,POOJ 4DBS$SVGU -B[BSVT
Lazarus, G0032 • Named by Novetta, 2016-02-24 - Presumably a
ff ected by “God’s Apostles” in operation Blockbuster - Returned from the dead in the Bible • Represent the entire DPRK threat actor
ScarCurft, APT37, G0067 • Named by Kaspersky, 2016-06-17 - Variations
on the malware repository domain, “scarcroft[.]net” • Targeted the North Korean defectors
BlueNoroff, APT38, G0082 • Named by Kaspersky, 2017-04-03 - Variations
on the malware fi lename, “nro ff _b.exe” in Bangladesh Central Bank Heist • Follow the money
Kimsuky, APT43, G0094 • Named by Kaspersky, 2013-09-11 - Russianized
version of the email sender name, “kimsukyang”(ӣࣼন) - Initially announced as an operation code name • “The king of the spear-phishing”
Andariel, G0138 • Named by FSI, 2017-07-27 - The act
1 boss character in the game, Diablo II • Exploit centralized management software • Targeted U.S. healthcare with ransomware
Konni • Named by Cisco Talos, 2017-05-03 - Initially Introduce
as a malware family name • Spear phishing targeting South Korea
Notable activities ,,/1 .', #JUQPJOU %SBHPO&Y #BOLPG7BMFUUB 2009 2010 2023
2021 2011 2012 2013 2014 2022 2015 2016 2017 2018 2019 2020 %%P4 %%P4 $ZCFS5FSSPS $ZCFS5FSSPS 4POZ1JDUVSFT&OU 4FPVM.FUSP ,)/1 #BOHMBEFTI$FOUSBM#BOL 4UBOEBSE#BOL $/#7 ,/' 6OJPO#BOL #BODP3FQVCMJDB "L#BOL *OJUFDI *OUFSQBSL %4.& 4,)BOKJO %FGFOTF/FUXPSL 8BOOB$SZ3BOTPNXBSF /*$"TJB#BOL )FSNFT3BOTPNXBSF '&*# .BSJOF$IBJO /JDF)BTI $FOUSBM"NFSJDBO0OMJOF$BTJOP #JUIVNC $IPOHIP&BTZDBTI :BQJ[PO -BCPS6OJPOT :BQJ[PO:PVCJU )BOBUPVS 6OLOPXO104 $PJOJT 'BTU$BTI $PJO$IFDL 3FECBOD #BOL*TMBNJ )4#$.BMUB ;BJG $PTNPT#BOL #BOPEF$IJMF .FUSPMJOY #BOL3BLZBU 7)%3BOTPNXBSF 'BTU$BTI &UFSCBTF ,V$PJO ,"&3* ,"* 4/6) %4.& $9 "UPNJD8BMMFU +VNQ$MPVE "MQIBQP $PJOT1BE 4UBLFDPN $PJO&Y )MZ(ITU3BOTPNXBSF .BVJ3BOTPNXBSF "YJF*OGJOJUZ )BSNPOZ#SJEHF 2VCJU'JOBODF %"1" 4FKPOH*OTUJUVUF #JUIVNC 34VQQPSU 8BWF4USJOH (#/,$FOUFS #JUIVNC .BSLBOZ 6QCJU #BODPEFM"VTUSP 5JFO1IPOH#BOL +PPOHBOHJMCP -JRVJE ,".4 )%"$ 8J[7FSB /)#BOL
Notable activities by motivation 0 10 20 30 2009 2010
2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 Destruction Espionage DataBreach FinancialGain Wateringhole SupplyChain
Worldmap Others 55% Viet Nam 2% India 5% Japan 5%
United States 8% Korea, Republic of 25%
Their favorites • Initial Access - T1195 Supply Chain Compromise
- T1189 Drive-by Compromise - T1566 Phishing • Lateral Movement - T1210 Exploitation of Remote Services
@lazarusholic https://lazarus.day Is he everywhere? Background Images: Unsplash Marek Piwnicki