Summary:
A malicious campaign mounted by the North Korea-linked Lazarus Group targeted energy providers around the world, including those based in the United States, Canada, and Japan, between February and July 2022. The campaign is meant to infiltrate organizations around the world for establishing long-term access and subsequently exfiltrating data of interest to the adversary's nation-state. Some elements of the espionage attacks have already entered public domain While these attacks previously led to the instrumentation of Preft and NukeSped implants, the latest attack wave is notable for employing two other pieces of malware, VSingle, an HTTP bot which executes arbitrary code from a remote network, and a Golang backdoor called YamaBot. Although the same tactics have been applied in both attacks, the resulting malware implants deployed have been distinct from one another, indicating the wide variety of implants available at the disposal of Lazarus. Other tactics embraced by the group include credential harvesting via tools like Mimikatz and Procdump, disabling antivirus components, and reconnaissance of the Active Directory services, and even taking steps to clean-up their traces after activating the backdoors on the endpoint.[/subscribe_to_unlock_form]
Summary:
A malicious campaign mounted by the North Korea-linked Lazarus Group targeted energy providers around the world, including those based in the United States, Canada, and Japan, between February and July 2022. The campaign is meant to infiltrate organizations around the world for establishing long-term access and subsequently exfiltrating data of interest to the adversary's nation-state. Some elements of the espionage attacks have already entered public domain While these attacks previously led to the instrumentation of Preft and NukeSped implants, the latest attack wave is notable for employing two other pieces of malware, VSingle, an HTTP bot which executes arbitrary code from a remote network, and a Golang backdoor called YamaBot. Although the same tactics have been applied in both attacks, the resulting malware implants deployed have been distinct from one another, indicating the wide variety of implants available at the disposal of Lazarus. Other tactics embraced by the group include credential harvesting via tools like Mimikatz and Procdump, disabling antivirus components, and reconnaissance of the Active Directory services, and even taking steps to clean-up their traces after activating the backdoors on the endpoint.[emaillocker id="1283"]

References:
The following reports contain further technical details:
https://thehackernews.com/2022/09/north-korean-lazarus-hackers-targeting.html
https://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
[/emaillocker]