Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
He is everywhere: A tale of Lazarus and his family
Search
JeongGak Lyu
October 17, 2023
Technology
42
0
Share
He is everywhere: A tale of Lazarus and his family
This talk was presented at Hack.lu & CTI Summit 2023.
JeongGak Lyu
October 17, 2023
More Decks by JeongGak Lyu
See All by JeongGak Lyu
Exploiting Trust: When a Trusted Security Solution Becomes a DPRK Trojan Horse
jglyu
0
10
공격자의 시선에서 바라본 금융보안: 사이버 복원력 강화를 위한 레드티밍 전략
jglyu
0
41
Follow the Clues: Everyday is lazarus.day
jglyu
0
21
금융분야 침해사고 동향 및 시사점
jglyu
0
19
Other Decks in Technology
See All in Technology
GitHub Copilot のこれまでとこれから: From Copilot to Collaborative Agents
yuriemori
1
230
Agentic Design Patterns
glaforge
0
250
A Harness for Behaviour: how to get AI to generate code that does what we intend, or "TDD in the age of AI"
xpmatteo
0
490
Sony_KMP_Journey_KotlinConf2026
sony
0
160
Typiaで配信JSONの安全性を構造的に担保する(TSKaigi2026)
righttouch
PRO
1
190
インフラが苦手でも大丈夫! 紙芝居 Kubernetes -WWGT 10周年編-
aoi1
1
300
電子辞書Brainをネットに繋げてみた(自力編)
raspython3
0
300
個人AIからチームAIへ:開発における品質と生産性の再設計
moongift
PRO
0
270
責任あるソフトウェアエンジニアリングの紹介4章・5章 / RSE_Ch4-5
ido_kara_deru
0
360
Kaggle未経験社員をメダリストに育てる「AIドラゴン桜」
lycorptech_jp
PRO
0
650
ポスター発表&デモと総括 / Poster Presentations & Demonstrations and Summary
ks91
PRO
0
150
大規模災害時でも高い信頼性を維持するアプリケーション基盤の実現/nikkei-tech-talk46
nikkei_engineer_recruiting
0
110
Featured
See All Featured
Code Review Best Practice
trishagee
74
20k
Reality Check: Gamification 10 Years Later
codingconduct
0
2.2k
The Web Performance Landscape in 2024 [PerfNow 2024]
tammyeverts
12
1.2k
RailsConf & Balkan Ruby 2019: The Past, Present, and Future of Rails at GitHub
eileencodes
141
35k
個人開発の失敗を避けるイケてる考え方 / tips for indie hackers
panda_program
122
21k
A better future with KSS
kneath
240
18k
The AI Revolution Will Not Be Monopolized: How open-source beats economies of scale, even for LLMs
inesmontani
PRO
3
3.5k
Claude Code どこまでも/ Claude Code Everywhere
nwiizo
65
55k
Groundhog Day: Seeking Process in Gaming for Health
codingconduct
0
190
Have SEOs Ruined the Internet? - User Awareness of SEO in 2025
akashhashmi
0
350
[Rails World 2023 - Day 1 Closing Keynote] - The Magic of Rails
eileencodes
38
2.9k
Java REST API Framework Comparison - PWX 2021
mraible
34
9.3k
Transcript
2023-10-17, @lazarusholic JeongGak Lyu, Financial Security Institute He is everywhere
A tale of Lazarus and his family
Who are Lazarus and his family? • Behind Infamous Cyber
Incidents • Democratic People's Republic of Korea(DPRK, North Korea) stated- sponsored Threat Actors • Most Wanted Threat Actors in the World
# of posts by year
Top 10 authors "IOMBC &454FDVSJUZ ,BTQFSTLZ
/4)$ 64$*4" ,3$&35 2JIPP 4BLBJ &4&5 )BVSJ
Lazarus by the numbers Aliases (Associated Groups) 143 Posts Authors
Notable Activities 1,638 329 109 Victim Countries 57
MISP Threat Actor Galaxy https://www.misp-project.org/galaxy.html
MITRE ATT&CK Groups %13, 5ISFBU"DUPST ( -B[BSVT(SPVQ -BCZSJOUI$IPMMJNB )JEEFO$PCSB (VBSEJBOTPG1FBDF
;*/$ /JDLFM"DBEFNZ "15 ( 3JDPDIFU$IPMMJNB *OLZ4RVJE 4DBS$SVGU 3FBQFS (SPVQ 5&.13FBQFS "15 ( 4UBSEVTU$IPMMJNB #FBHMF#PZ[ #MVF/PSPGG /JDLFM(MBETUPOF ,JNTVLZ ( 7FMWFU$IPMMJNB 5IBMMJVN #MBDL#BOTIFF 4UPMFO1FODJM "OEBSJFM ( 4JMFOU$IPMMJNB https://attack.mitre.org/groups/
Mandiant ,*. 3(# 5&.1)FSNJU "15 "15 "OEBSJFM .JOJTUSZPG 4UBUVF4FDVSJUZ "15
0GGJDF 3FTFBSDI 3FTFBSDI SE#VSFBV 3(# "OEBSJFM ,JNTVLZ -B[BSVT ,*. UN Security Council https://www.mandiant.com/resources/mapping-dprk-groups-to-government https://www.mandiant.com/resources/blog/north-korea-cyber-structure-alignment-2023 https://undocs.org/Home/Mobile?FinalSymbol=S%2F2023%2F171 ,*. 3(# "OEBSJFM 5&.1)FSNJU "15 #VSFBV -BC SE#VSFBV $FSJVN ,JNTVLZ UI#VSFBV .JOJTUSZPG 4UBUVF4FDVSJUZ "15
Naming conventions: Simple • Qihoo360: APT-C-[N] • Cisco Talos: Group[N]
• Elastic: REF[N] • IBM: ITG[N], Hive[N] • Mandiant: APT[N], UNC[N] • Microsoft: Element Name(Deprecated) • NSHC: Sector[A][N] • Proofpoint: TA[N] • Recorded Future: TAG-[N] • Secureworks: CTG-[N] • Thales Group: ATK[N] • Qianxin: APT-Q-[N]
Naming conventions: State-sponsored China DPRK Iran Russia Crowd Strike Panda
Chollima Kitten Bear Microsoft Typhoon Sleet Sandstrom Blizzard NSHC SectorB SectorA SectorD SectorC Paloalto Networks Taurus Pisces Serpens Ursa PWC Red Black Yellow Blue Secureworks Bronze Nickel Cobalt Iron
Naming conventions: DPRK • Ahnlab: Red [Dot | Eyes] •
CrowdStrike: [Labyrinth | Ricochet | Silent | Startdust | Velvet] Chollima • KRCERT: Red [Carpet | Kim | Light] • Microsoft: [Citrine | Diamond | Emerald | Jade | Onyx | Opal | Pearl | Ruby | Sapphire] Sleet • NSHC: SectorA[01 - 07] • Paloalto Networks: [Crooked | Moldy | Selective] Pisces • PWC: Black [Alicanto | Artemis | Banshee | Dev2 | Shoggoth] • Secureworks: Nickel [Academy | Foxcroft | Hyatt | Kimball]
Lazarus, and his family #MVF/PSPGG ,JNTVLZ "OEBSJFM ,POOJ 4DBS$SVGU -B[BSVT
Lazarus, G0032 • Named by Novetta, 2016-02-24 - Presumably a
ff ected by “God’s Apostles” in operation Blockbuster - Returned from the dead in the Bible • Represent the entire DPRK threat actor
ScarCurft, APT37, G0067 • Named by Kaspersky, 2016-06-17 - Variations
on the malware repository domain, “scarcroft[.]net” • Targeted the North Korean defectors
BlueNoroff, APT38, G0082 • Named by Kaspersky, 2017-04-03 - Variations
on the malware fi lename, “nro ff _b.exe” in Bangladesh Central Bank Heist • Follow the money
Kimsuky, APT43, G0094 • Named by Kaspersky, 2013-09-11 - Russianized
version of the email sender name, “kimsukyang”(ӣࣼন) - Initially announced as an operation code name • “The king of the spear-phishing”
Andariel, G0138 • Named by FSI, 2017-07-27 - The act
1 boss character in the game, Diablo II • Exploit centralized management software • Targeted U.S. healthcare with ransomware
Konni • Named by Cisco Talos, 2017-05-03 - Initially Introduce
as a malware family name • Spear phishing targeting South Korea
Notable activities ,,/1 .', #JUQPJOU %SBHPO&Y #BOLPG7BMFUUB 2009 2010 2023
2021 2011 2012 2013 2014 2022 2015 2016 2017 2018 2019 2020 %%P4 %%P4 $ZCFS5FSSPS $ZCFS5FSSPS 4POZ1JDUVSFT&OU 4FPVM.FUSP ,)/1 #BOHMBEFTI$FOUSBM#BOL 4UBOEBSE#BOL $/#7 ,/' 6OJPO#BOL #BODP3FQVCMJDB "L#BOL *OJUFDI *OUFSQBSL %4.& 4,)BOKJO %FGFOTF/FUXPSL 8BOOB$SZ3BOTPNXBSF /*$"TJB#BOL )FSNFT3BOTPNXBSF '&*# .BSJOF$IBJO /JDF)BTI $FOUSBM"NFSJDBO0OMJOF$BTJOP #JUIVNC $IPOHIP&BTZDBTI :BQJ[PO -BCPS6OJPOT :BQJ[PO:PVCJU )BOBUPVS 6OLOPXO104 $PJOJT 'BTU$BTI $PJO$IFDL 3FECBOD #BOL*TMBNJ )4#$.BMUB ;BJG $PTNPT#BOL #BOPEF$IJMF .FUSPMJOY #BOL3BLZBU 7)%3BOTPNXBSF 'BTU$BTI &UFSCBTF ,V$PJO ,"&3* ,"* 4/6) %4.& $9 "UPNJD8BMMFU +VNQ$MPVE "MQIBQP $PJOT1BE 4UBLFDPN $PJO&Y )MZ(ITU3BOTPNXBSF .BVJ3BOTPNXBSF "YJF*OGJOJUZ )BSNPOZ#SJEHF 2VCJU'JOBODF %"1" 4FKPOH*OTUJUVUF #JUIVNC 34VQQPSU 8BWF4USJOH (#/,$FOUFS #JUIVNC .BSLBOZ 6QCJU #BODPEFM"VTUSP 5JFO1IPOH#BOL +PPOHBOHJMCP -JRVJE ,".4 )%"$ 8J[7FSB /)#BOL
Notable activities by motivation 0 10 20 30 2009 2010
2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 Destruction Espionage DataBreach FinancialGain Wateringhole SupplyChain
Worldmap Others 55% Viet Nam 2% India 5% Japan 5%
United States 8% Korea, Republic of 25%
Their favorites • Initial Access - T1195 Supply Chain Compromise
- T1189 Drive-by Compromise - T1566 Phishing • Lateral Movement - T1210 Exploitation of Remote Services
@lazarusholic https://lazarus.day Is he everywhere? Background Images: Unsplash Marek Piwnicki