Pradhan, A. (2022, February 8). LolZarus: Lazarus Group Incorporating Lolbins into Campaigns. Retrieved March 22, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupLazarus Group | Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names. |
| T1036.003 Rename Legitimate Utilities |
GroupLazarus Group | Lazarus Group has renamed system utilities such as |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLazarus Group | Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files. |
| T1047 Windows Management Instrumentation |
GroupLazarus Group | Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement. |
| T1053.005 Scheduled Task |
GroupLazarus Group | Lazarus Group has used |
| T1059.003 Windows Command Shell |
GroupLazarus Group | Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system. |
| T1059.005 Visual Basic |
GroupLazarus Group | Lazarus Group has used VBA and embedded macros in Word documents to execute malicious code. |
| T1071.001 Web Protocols |
GroupLazarus Group | Lazarus Group has conducted C2 over HTTP and HTTPS. |
| T1083 File and Directory Discovery |
GroupLazarus Group | Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1106 Native API |
GroupLazarus Group | Lazarus Group has used the Windows API |
| T1140 Deobfuscate/Decode Files or Information |
GroupLazarus Group | Lazarus Group has used shellcode within macros to decrypt and manually map DLLs and shellcode into memory at runtime. |
| T1202 Indirect Command Execution |
GroupLazarus Group | Lazarus Group persistence mechanisms have used |
| T1204.002 Malicious File |
GroupLazarus Group | Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email. |
| T1218 System Binary Proxy Execution |
GroupLazarus Group | Lazarus Group lnk files used for persistence have abused the Windows Update Client ( |
| T1218.005 Mshta |
GroupLazarus Group | Lazarus Group has used |
| T1566.001 Spearphishing Attachment |
GroupLazarus Group | Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents. |
| T1574.013 KernelCallbackTable |
GroupLazarus Group | Lazarus Group has abused the |
| T1620 Reflective Code Loading |
GroupLazarus Group | Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.