Lazarus Group is a notorious APT hacker group believed to be state-sponsored by North Korea, primarily linked to the country’s intelligence agency.
This group has been involved in a wide range of cybercriminal activities since at least 2009, and it’s known for its sophisticated attacks on various targets like financial institutions, corporations, and critical infrastructure.
Cybersecurity researchers at Palo Alto Networks recently identified that there are six North Korean threat groups under the umbrella of the Lazarus group.
Here below we have mentioned all those six groups:-
North Korean cyber threat groups that are operating under the Reconnaissance General Bureau (RGB) were found to be deploying a sophisticated malware arsenal across all the major platform, Windows, macOS, and Linux.
Decoding Compliance: What CISOs Need to Know – Join Free Webinar
Notable examples include:-
These malware families present advanced techniques like reflective loading, multi-stage payloads, and encrypted command and control (C2) communication.
For instance, Comebacker uses HTTP POST requests with randomly generated parameter names for C2, while the PondRAT targets both macOS and Linux systems.
The malware ecosystem includes specialized tools like “ObjCShellz” (an Objective-C backdoor) and “Fullhouse” (a C/C++ HTTP backdoor).
Besides this, groups like Alluring Pisces (APT38), Gleaming Pisces, and Selective Pisces (ZINC) have executed high-profile attacks, including the “2014 Sony Pictures hack” and “2017 WannaCry ransomware campaign.”
The malware families discussed include Remote Access Trojans (RATs), keyloggers, backdoors, and information stealers.
As such state-sponsored cyber activities, that frequently focus on critical infrastructure, financial and government targets, it is important that organizations develop ready comprehensive cyber strategies, Palo Alto said.
Here below we have mentioned all the mitigations:-
Simulating Cyberattack Scenarios With All-in-One Cybersecurity Platform – Watch Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…