Summary:
The long-running campaign known as DeathNote, the North Korean threat actor known as the Lazarus Group has been seen to rapidly adapt its tools and methods while also adjusting its focus. These attacks were aimed against a South Korean think tank and a Latvian distributor of IT asset monitoring solutions, the latter of which involved the misuse of genuine security software that is extensively used in that nation. Recent attacks have targeted the automotive, academic, and defense industries in Eastern Europe and other parts of the world, in what is viewed as a "significant" diversion from the nation-state adversary's well-known pattern of focusing on the bitcoin industry. At this point, the actor changed every fake paper to a job description for a defense contractor or a diplomat. This point the actor changed every decoy document to a job description for a defense contractor or a diplomat. According to a Researcher in October 2021, the Lazarus Group's attacks on the defense sector as a whole are linked to the targeting of the automotive and academic sectors and resulted in the use of the implants BLINDINGCAN (also known as AIRDRY or ZetaNile) and COPPERHEDGE.[/subscribe_to_unlock_form]
Summary:
The long-running campaign known as DeathNote, the North Korean threat actor known as the Lazarus Group has been seen to rapidly adapt its tools and methods while also adjusting its focus. These attacks were aimed against a South Korean think tank and a Latvian distributor of IT asset monitoring solutions, the latter of which involved the misuse of genuine security software that is extensively used in that nation. Recent attacks have targeted the automotive, academic, and defense industries in Eastern Europe and other parts of the world, in what is viewed as a "significant" diversion from the nation-state adversary's well-known pattern of focusing on the bitcoin industry. At this point, the actor changed every fake paper to a job description for a defense contractor or a diplomat. This point the actor changed every decoy document to a job description for a defense contractor or a diplomat. According to a Researcher in October 2021, the Lazarus Group's attacks on the defense sector as a whole are linked to the targeting of the automotive and academic sectors and resulted in the use of the implants BLINDINGCAN (also known as AIRDRY or ZetaNile) and COPPERHEDGE.[emaillocker id="1283"]

Execution-Flow
They named the current cluster DeathNote because the malware that downloads additional payloads goes by the name Dn.dll or Dn64.dll. In order to install the Manuscrypt (also known as NukeSped) backdoor on the compromised machine, the Manuscrypt (aka NukeSped) backdoor is often dropped via email messages with bitcoin mining-themed baits to potential targets. To start its harmful routine in a different attack chain, the threat actor used a trojanized edition of the popular PDF reader program SumatraPDF Reader. Microsoft previously revealed that The Lazarus Group used malicious PDF reader applications. The implanted backdoor is capable of executing a retrieved payload with named-pipe communication, it's also responsible for gathering and reporting the victim's information.
The Lazarus Group was also implicated in a successful hack of a different defence contractor in Africa that occurred in July. In that incident, a "suspicious PDF application" was distributed through Skype before dropping the ThreatNeedle backdoor version and the ForestTiger data exfiltration implant.
The Lazarus organisation is a well-known and expert threat actor, Organisations must be vigilant and take preventive action to guard against the Lazarus group's nefarious actions as it keeps improving its tactics.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/04/lazarus-hacker-group-evolves-tactics.html
[/emaillocker]