ATT&CKReferencesClearSky Lazarus Aug 2020

ClearSky Lazarus Aug 2020

ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples43

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host.

T1005
Data from Local System
MalwareDRATzarus

DRATzarus can collect information from a compromised host.

T1018
Remote System Discovery
MalwareDRATzarus

DRATzarus can search for other machines connected to compromised host and attempt to map the network.

T1027
Obfuscated Files or Information
MalwareDRATzarus

DRATzarus can be partly encrypted with XOR.

T1027.002
Software Packing
MalwareDRATzarus

DRATzarus's dropper can be packed with UPX.

T1027.002
Software Packing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.

T1027.013
Encrypted/Encoded File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.

T1033
System Owner/User Discovery
MalwareDRATzarus

DRATzarus can obtain a list of users from an infected machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareDRATzarus

DRATzarus has been named `Flash.exe`, and its dropper has been named `IExplorer`.

T1041
Exfiltration Over C2 Channel
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers.

T1057
Process Discovery
MalwareDRATzarus

DRATzarus can enumerate and examine running processes to determine if a debugger is present.

T1059.005
Visual Basic
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant.

T1071.001
Web Protocols
MalwareDRATzarus

DRATzarus can use HTTP or HTTPS for C2 communications.

T1083
File and Directory Discovery
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters.

T1105
Ingress Tool Transfer
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
MalwareDRATzarus

DRATzarus can deploy additional tools onto an infected machine.

T1106
Native API
MalwareDRATzarus

DRATzarus can use various API calls to see if it is running in a sandbox.

T1124
System Time Discovery
MalwareDRATzarus

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to inspect system time.

T1204.001
Malicious Link
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access.

T1204.002
Malicious File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors.

T1218.011
Rundll32
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`.

T1221
Template Injection
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file.

T1497.001
System Checks
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that conducted a variety of system checks to detect sandboxes or VMware services.

T1497.003
Time Based Checks
MalwareDRATzarus

DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade
detection.

T1497.003
Time Based Checks
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services.

T1534
Internal Spearphishing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization.

T1566.001
Spearphishing Attachment
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers.

T1566.002
Spearphishing Link
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email.

T1566.003
Spearphishing via Service
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs.

T1567.002
Exfiltration to Cloud Storage
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox.

T1583.006
Web Services
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive.

T1584.004
Server
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools.

T1585.001
Social Media Accounts
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts.

T1587.001
Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.

T1588.002
Tool
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli.

T1589
Gather Victim Identity Information
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets.

T1591
Gather Victim Org Information
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets.

T1591.004
Identify Roles
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements.

T1608.001
Upload Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used compromised servers to host malware.

T1614.001
System Language Discovery
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group deployed malware designed not to run on computers set to Korean, Japanese, or Chinese in Windows language preferences.

T1622
Debugger Evasion
MalwareDRATzarus

DRATzarus can use `IsDebuggerPresent` to detect whether a debugger is present on a victim.

T1622
Debugger Evasion
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that used the `IsDebuggerPresent` call to detect debuggers.

T1684.001
Impersonation
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group impersonated HR hiring personnel through LinkedIn messages and conducted interviews with victims in order to deceive them into downloading malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.