ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

North Korean State-Backed Hackers Utilize Known Software Vulnerabilities

Kyle by Kyle
October 31, 2023
in Malware
Reading Time: 3 mins read
North Korean Lazarus group 1
Share on FacebookShare on Twitter

In a recent investigation conducted by Kaspersky, cybersecurity researchers have uncovered an advanced persistent threat campaign conducted by the notorious Lazarus group, a North Korean state-sponsored hacking collective. The group has been exploiting well-documented vulnerabilities in an undisclosed software product, despite the existence of reported vulnerabilities and available patches.

This campaign, which has had a global impact, centers on the utilization of known flaws in a previous version of undisclosed software. These flaws, despite being reported and addressed through patches, have been exploited to encrypt web communications using digital certificates. The Lazarus group leveraged these vulnerabilities as an entry point to infiltrate organizations and encrypt web communication through digital certificates, as confirmed by Kaspersky’s findings.

The Lazarus group, believed to be under the auspices of the Democratic People’s Republic of Korea (DPRK), has a well-established track record of using cyber intrusions for both espionage and financial crime, all with the aim of consolidating power and financing their cyber and kinetic capabilities. Google’s Mandiant threat intelligence group has reported extensively on North Korea’s association with multiple state-sponsored hacking teams, both domestically and internationally. These teams are involved in intelligence-gathering activities against allies, adversaries, and defectors, as well as conducting bank heists and cryptocurrency theft.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

In past reports, the United Nations has accused North Korea of channeling stolen funds into the country’s long-range missile and nuclear weapons programs and enriching its leadership.

To execute their malicious activities, the Lazarus group deployed the SIGNBT malware to compromise victims and employed the well-known LPEClient tool. This tool, previously observed targeting defense contractors, nuclear engineers, and the cryptocurrency sector, was also identified in the infamous 3CX supply chain attack. According to Kaspersky researchers, the SIGNBT malware served as the initial point of infection, playing a pivotal role in profiling victims and delivering the payload.

It’s worth noting that the developers of the undisclosed software had been targeted by Lazarus on multiple occasions in the past, suggesting the threat actor’s unwavering persistence and motivation. Their likely objectives include stealing valuable source code or tampering with the software supply chain.

Seongsu Park, lead security researcher at Kaspersky, emphasized the advanced capabilities and unwavering motivation of the Lazarus group. “They operate on a global scale, targeting a wide range of industries with a diverse toolkit of methods. This signifies an ongoing and evolving threat that demands heightened vigilance,” Park stated.

Kaspersky’s Malware Analysis

Kaspersky revealed that in mid-July, a series of attacks involving the vulnerable software was detected, with post-exploitation activities occurring within the legitimate software’s processes. Researchers found that the SIGNBT malware, along with a shellcode, was present in the compromised security software of a victim’s system. This shellcode was responsible for executing a Windows executable file directly in memory.

The threat actor employed various tactics to establish and maintain persistence on compromised systems. This included creating a file named ualapi.dll in the system folder, which would be automatically loaded by the spoolsv.exe process during each system boot. Additionally, Lazarus hackers made registry entries to facilitate the execution of legitimate files for malicious side-loading, ensuring a resilient persistence mechanism.

Hijacking the spoolsv.exe process has been a long-standing strategy for Lazarus, known for loading a ualapi.dll file after each system reboot. The file’s development utilized a public source code called Shareaza Torrent Wizard, a typical approach adopted by the Lazarus group. This involves using public source code as a foundation and injecting specific malicious functions into it.

Lazarus also deployed additional malware, including tools such as LPEClient and credential-dumping utilities, to victim machines. This toolset was employed to collect victim information and download additional payloads from a remote server for execution in memory.

As previously noted, the Lazarus group has increasingly utilized advanced techniques to enhance stealth and evade detection, including disabling user-mode syscall hooking and restoring system library memory sections.

Tags: Lazarus
Previous Post

Bibi-Linux Malware Unleashed on Israeli Linux Systems: A New Data-Wiping Threat

Next Post

New Wave of Malicious NuGet Packages Impacts .NET Developers

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.