Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
He is everywhere: A tale of Lazarus and his family
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
JeongGak Lyu
October 17, 2023
Technology
0
29
He is everywhere: A tale of Lazarus and his family
This talk was presented at Hack.lu & CTI Summit 2023.
JeongGak Lyu
October 17, 2023
Tweet
Share
More Decks by JeongGak Lyu
See All by JeongGak Lyu
공격자의 시선에서 바라본 금융보안: 사이버 복원력 강화를 위한 레드티밍 전략
jglyu
0
33
Follow the Clues: Everyday is lazarus.day
jglyu
0
16
금융분야 침해사고 동향 및 시사점
jglyu
0
15
Other Decks in Technology
See All in Technology
「Blue Team Labs Online」入門 - みんなで挑むログ解析バトル
v_avenger
0
130
作りっぱなしで終わらせない! 価値を出し続ける AI エージェントのための「信頼性」設計 / Designing Reliability for AI Agents that Deliver Continuous Value
aoto
PRO
2
250
Oracle Database@Google Cloud:サービス概要のご紹介
oracle4engineer
PRO
5
1.1k
Evolution of Claude Code & How to use features
oikon48
1
560
マルチプレーンGPUネットワークを実現するシャッフルアーキテクチャの整理と考察
markunet
2
220
オレ達はAWS管理をやりたいんじゃない!開発の生産性を爆アゲしたいんだ!!
wkm2
4
460
マルチロールEMが実践する「組織のレジリエンス」を高めるための組織構造と人材配置戦略
coconala_engineer
3
670
タスク管理も1on1も、もう「管理」じゃない ― KiroとBedrock AgentCoreで変わった"判断の仕事"
yusukeshimizu
5
2.3k
元エンジニアPdM、IDEが恋しすぎてCursorに全業務を集約したら、スライド作成まで爆速になった話
doiko123
1
530
DevOpsエージェントで実現する!! AWS Well-Architected(W-A) を実現するシステム設計 / 20260307 Masaki Okuda
shift_evolve
PRO
3
420
情シスのための生成AI実践ガイド2026 / Generative AI Practical Guide for Business Technology 2026
glidenote
0
170
JAWS DAYS 2026 楽しく学ぼう!ストレージ 入門
yoshiki0705
2
130
Featured
See All Featured
Context Engineering - Making Every Token Count
addyosmani
9
740
Un-Boring Meetings
codingconduct
0
220
Save Time (by Creating Custom Rails Generators)
garrettdimon
PRO
32
2.4k
Designing for Performance
lara
611
70k
Navigating the Design Leadership Dip - Product Design Week Design Leaders+ Conference 2024
apolaine
0
220
B2B Lead Gen: Tactics, Traps & Triumph
marketingsoph
0
73
Dealing with People You Can't Stand - Big Design 2015
cassininazir
367
27k
Impact Scores and Hybrid Strategies: The future of link building
tamaranovitovic
0
230
The Web Performance Landscape in 2024 [PerfNow 2024]
tammyeverts
12
1.1k
Paper Plane (Part 1)
katiecoart
PRO
0
5.4k
Exploring the relationship between traditional SERPs and Gen AI search
raygrieselhuber
PRO
2
3.7k
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
37
6.3k
Transcript
2023-10-17, @lazarusholic JeongGak Lyu, Financial Security Institute He is everywhere
A tale of Lazarus and his family
Who are Lazarus and his family? • Behind Infamous Cyber
Incidents • Democratic People's Republic of Korea(DPRK, North Korea) stated- sponsored Threat Actors • Most Wanted Threat Actors in the World
# of posts by year
Top 10 authors "IOMBC &454FDVSJUZ ,BTQFSTLZ
/4)$ 64$*4" ,3$&35 2JIPP 4BLBJ &4&5 )BVSJ
Lazarus by the numbers Aliases (Associated Groups) 143 Posts Authors
Notable Activities 1,638 329 109 Victim Countries 57
MISP Threat Actor Galaxy https://www.misp-project.org/galaxy.html
MITRE ATT&CK Groups %13, 5ISFBU"DUPST ( -B[BSVT(SPVQ -BCZSJOUI$IPMMJNB )JEEFO$PCSB (VBSEJBOTPG1FBDF
;*/$ /JDLFM"DBEFNZ "15 ( 3JDPDIFU$IPMMJNB *OLZ4RVJE 4DBS$SVGU 3FBQFS (SPVQ 5&.13FBQFS "15 ( 4UBSEVTU$IPMMJNB #FBHMF#PZ[ #MVF/PSPGG /JDLFM(MBETUPOF ,JNTVLZ ( 7FMWFU$IPMMJNB 5IBMMJVN #MBDL#BOTIFF 4UPMFO1FODJM "OEBSJFM ( 4JMFOU$IPMMJNB https://attack.mitre.org/groups/
Mandiant ,*. 3(# 5&.1)FSNJU "15 "15 "OEBSJFM .JOJTUSZPG 4UBUVF4FDVSJUZ "15
0GGJDF 3FTFBSDI 3FTFBSDI SE#VSFBV 3(# "OEBSJFM ,JNTVLZ -B[BSVT ,*. UN Security Council https://www.mandiant.com/resources/mapping-dprk-groups-to-government https://www.mandiant.com/resources/blog/north-korea-cyber-structure-alignment-2023 https://undocs.org/Home/Mobile?FinalSymbol=S%2F2023%2F171 ,*. 3(# "OEBSJFM 5&.1)FSNJU "15 #VSFBV -BC SE#VSFBV $FSJVN ,JNTVLZ UI#VSFBV .JOJTUSZPG 4UBUVF4FDVSJUZ "15
Naming conventions: Simple • Qihoo360: APT-C-[N] • Cisco Talos: Group[N]
• Elastic: REF[N] • IBM: ITG[N], Hive[N] • Mandiant: APT[N], UNC[N] • Microsoft: Element Name(Deprecated) • NSHC: Sector[A][N] • Proofpoint: TA[N] • Recorded Future: TAG-[N] • Secureworks: CTG-[N] • Thales Group: ATK[N] • Qianxin: APT-Q-[N]
Naming conventions: State-sponsored China DPRK Iran Russia Crowd Strike Panda
Chollima Kitten Bear Microsoft Typhoon Sleet Sandstrom Blizzard NSHC SectorB SectorA SectorD SectorC Paloalto Networks Taurus Pisces Serpens Ursa PWC Red Black Yellow Blue Secureworks Bronze Nickel Cobalt Iron
Naming conventions: DPRK • Ahnlab: Red [Dot | Eyes] •
CrowdStrike: [Labyrinth | Ricochet | Silent | Startdust | Velvet] Chollima • KRCERT: Red [Carpet | Kim | Light] • Microsoft: [Citrine | Diamond | Emerald | Jade | Onyx | Opal | Pearl | Ruby | Sapphire] Sleet • NSHC: SectorA[01 - 07] • Paloalto Networks: [Crooked | Moldy | Selective] Pisces • PWC: Black [Alicanto | Artemis | Banshee | Dev2 | Shoggoth] • Secureworks: Nickel [Academy | Foxcroft | Hyatt | Kimball]
Lazarus, and his family #MVF/PSPGG ,JNTVLZ "OEBSJFM ,POOJ 4DBS$SVGU -B[BSVT
Lazarus, G0032 • Named by Novetta, 2016-02-24 - Presumably a
ff ected by “God’s Apostles” in operation Blockbuster - Returned from the dead in the Bible • Represent the entire DPRK threat actor
ScarCurft, APT37, G0067 • Named by Kaspersky, 2016-06-17 - Variations
on the malware repository domain, “scarcroft[.]net” • Targeted the North Korean defectors
BlueNoroff, APT38, G0082 • Named by Kaspersky, 2017-04-03 - Variations
on the malware fi lename, “nro ff _b.exe” in Bangladesh Central Bank Heist • Follow the money
Kimsuky, APT43, G0094 • Named by Kaspersky, 2013-09-11 - Russianized
version of the email sender name, “kimsukyang”(ӣࣼন) - Initially announced as an operation code name • “The king of the spear-phishing”
Andariel, G0138 • Named by FSI, 2017-07-27 - The act
1 boss character in the game, Diablo II • Exploit centralized management software • Targeted U.S. healthcare with ransomware
Konni • Named by Cisco Talos, 2017-05-03 - Initially Introduce
as a malware family name • Spear phishing targeting South Korea
Notable activities ,,/1 .', #JUQPJOU %SBHPO&Y #BOLPG7BMFUUB 2009 2010 2023
2021 2011 2012 2013 2014 2022 2015 2016 2017 2018 2019 2020 %%P4 %%P4 $ZCFS5FSSPS $ZCFS5FSSPS 4POZ1JDUVSFT&OU 4FPVM.FUSP ,)/1 #BOHMBEFTI$FOUSBM#BOL 4UBOEBSE#BOL $/#7 ,/' 6OJPO#BOL #BODP3FQVCMJDB "L#BOL *OJUFDI *OUFSQBSL %4.& 4,)BOKJO %FGFOTF/FUXPSL 8BOOB$SZ3BOTPNXBSF /*$"TJB#BOL )FSNFT3BOTPNXBSF '&*# .BSJOF$IBJO /JDF)BTI $FOUSBM"NFSJDBO0OMJOF$BTJOP #JUIVNC $IPOHIP&BTZDBTI :BQJ[PO -BCPS6OJPOT :BQJ[PO:PVCJU )BOBUPVS 6OLOPXO104 $PJOJT 'BTU$BTI $PJO$IFDL 3FECBOD #BOL*TMBNJ )4#$.BMUB ;BJG $PTNPT#BOL #BOPEF$IJMF .FUSPMJOY #BOL3BLZBU 7)%3BOTPNXBSF 'BTU$BTI &UFSCBTF ,V$PJO ,"&3* ,"* 4/6) %4.& $9 "UPNJD8BMMFU +VNQ$MPVE "MQIBQP $PJOT1BE 4UBLFDPN $PJO&Y )MZ(ITU3BOTPNXBSF .BVJ3BOTPNXBSF "YJF*OGJOJUZ )BSNPOZ#SJEHF 2VCJU'JOBODF %"1" 4FKPOH*OTUJUVUF #JUIVNC 34VQQPSU 8BWF4USJOH (#/,$FOUFS #JUIVNC .BSLBOZ 6QCJU #BODPEFM"VTUSP 5JFO1IPOH#BOL +PPOHBOHJMCP -JRVJE ,".4 )%"$ 8J[7FSB /)#BOL
Notable activities by motivation 0 10 20 30 2009 2010
2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 Destruction Espionage DataBreach FinancialGain Wateringhole SupplyChain
Worldmap Others 55% Viet Nam 2% India 5% Japan 5%
United States 8% Korea, Republic of 25%
Their favorites • Initial Access - T1195 Supply Chain Compromise
- T1189 Drive-by Compromise - T1566 Phishing • Lateral Movement - T1210 Exploitation of Remote Services
@lazarusholic https://lazarus.day Is he everywhere? Background Images: Unsplash Marek Piwnicki