Lazarus Strikes Again, Attacks Supply Chain in South Korea

Date:

Share post:

Security researchers from ESET found cybercriminals linked to North-Korean Lazarus group targeting South Korean supply-chains. It was found that attackers exploited legitimate South Korean security software and digital certificates stolen from two different companies to distribute their malware. The hacker group also used illicitly obtained code to sign the malware samples.

Lazarus Supply Chain Attacks

ESET’s researchers stated that South Koreans are often asked to download additional security software while visiting government or banking services online. It is found that attackers abused this process to deploy Lazarus malware from a compromised legitimate website.

“To understand this novel supply-chain attack, you should be aware that WIZVERA VeraPort, referred to as an integration installation program, is a South Korean application that helps manage such additional security software. When WIZVERA VeraPort is installed, users receive and install all necessary software required by a specific website. Minimal user interaction is required to start such software installation. Usually this software is used by government and banking websites in South Korea. For some of these websites it’s mandatory to have WIZVERA VeraPort installed,” explains Anton Cherepanov, ESET researcher who led the investigation into the attack.

“The attackers camouflaged the Lazarus malware samples as legitimate software. These samples have similar file names, icons, and resources as legitimate South Korean software. It’s the combination of compromised websites with WIZVERA VeraPort support and specific VeraPort configuration options that allows attackers to perform this attack,” says Peter Kálnai, ESET researcher who analyzed the Lazarus attack with Cherepanov.

The Lazarus Timeline

The Lazarus hacking Group was involved in multiple cyberattacks earlier. In 2018, Kaspersky uncovered AppleJeus, a malicious operation by Lazarus Group to intrude on cryptocurrency exchanges and applications. In December 2019, the researchers discovered a malware dubbed as “Fileless” distributed by the Lazarus group.  For full story click here…

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

Stop Reviewing Faster: A Practical Model for AppSec at AI Speed

By Aparna Ash Himmatramka A developer using an AI assistant can ship a feature in an afternoon. In many...

Why I Go to the Dark Web Every Day

By Alex Holden, Chief Information Security Officer Hold Security For nearly two decades I made the Dark Web a...

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...