When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Cybersecurity researcher reveals Lazarus hacking technique

A new report compiled by cybersecurity researcher Shusei Tomonaga reveals Lazarus group's most formidable hacking techniques. The unit has in recent months been targeting Japanese companies.

The Lazarus hacker group has launched numerous disruptive campaigns against notable companies over the past few years. Reportedly backed by the North Korean regime, it is presently categorized as an advanced persistent threat by a collective of nations for its cybercriminal activities which have led to over a billion dollars in losses.

That said, a new report compiled by cybersecurity researcher Shusei Tomonaga shines a light on the unit’s most formidable hacking techniques. Many of them have been used in the group’s most recent campaign against Japanese firms. The report notes the use of the VSingle HTTP bot as a primary vector. The code is stealthily executed to initially embed itself onto a system and download obfuscation and exploitation software. Some versions of the bot also undertake DLL injection to hide their activity.

The Lazarus group also makes use of ValeforBeta, which works similarly to VSingle to transmit system information, send and download files. After successful infection of primary system processes, 3Proxy, Stunnel, and Plink tools are deployed to maintain a connection with the system, carry out mass analysis of infected devices, and allow control of vital resources.

The image shows the rebranded Opera on iOS
Next Article

Opera Touch rebranded as Opera on the iOS platform

Microsoft Edge logo on a dark background with blue and green waves under it
Previous Article

Microsoft, Google, and others join forces to improve browser compatibility

1 Comment

Load the comments and join the conversation!

Read the comments, ask the editors questions, show respect and join the conversation.

Click here