ATT&CKReferencesMcAfee Lazarus Jul 2020

McAfee Lazarus Jul 2020

Cashman, M. (2020, July 29). Operation North Star Campaign. Retrieved December 20, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples21

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host.

T1027.002
Software Packing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.

T1027.013
Encrypted/Encoded File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.

T1036.008
Masquerade File Type
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection.

T1059.003
Windows Command Shell
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell.

T1059.005
Visual Basic
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant.

T1071.001
Web Protocols
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers.

T1105
Ingress Tool Transfer
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.

T1106
Native API
GroupLazarus Group

Lazarus Group has used the Windows API ObtainUserAgentString to obtain the User-Agent from a compromised host to connect to a C2 server. Lazarus Group has also used various, often lesser known, functions to perform various types of Discovery and Process Injection.

T1106
Native API
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server.

T1204.002
Malicious File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors.

T1218.011
Rundll32
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`.

T1221
Template Injection
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file.

T1505.004
IIS Components
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components.

T1547.001
Registry Run Keys / Startup Folder
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence.

T1566.001
Spearphishing Attachment
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers.

T1573.001
Symmetric Cryptography
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server.

T1584.001
Domains
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure.

T1584.004
Server
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools.

T1587.001
Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.

T1608.001
Upload Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used compromised servers to host malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.