Lazarus Group Surfaces with Advanced Malware Framework
#1
Information 
Quote:The North Korea-linked APT known as Lazarus Group has debuted an advanced, multipurpose malware framework, called MATA, to target Windows, Linux and macOS operating systems.
 
Kaspersky researchers uncovered a series of attacks utilizing MATA (so-called because the malware authors themselves call their infrastructure MataNet), involving the infiltration of corporate entities around the world in a quest to steal customer databases and distribute ransomware. The framework consists of several components, such as a loader, an orchestrator (which manages and coordinates the processes once a device is infected) and plugins. And according to artifacts in the code, Lazarus has been using it since spring 2018.
 
“Malicious toolsets used to target multiple platforms are a rare breed, as they require significant investment from the developer,” explained Kaspersky analysts, in a report issued on Wednesday. “They are often deployed for long-term use, which results in increased profit for the actor through numerous attacks spread over time. In the cases discovered by Kaspersky, the MATA framework was able to target three platforms – Windows, Linux and macOS – indicating that the attackers planned to use it for multiple purposes.”

As far as victimology, known organizations hit by the MATA framework have been located in Germany, India, Japan, Korea, Turkey and Poland — indicating that the attacks cast a wide net. Moreover, those victims are in various sectors, and include a software development company, an e-commerce company and an internet service provider.

Read more: https://threatpost.com/lazarus-group-adv...rk/157636/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Kaspersky\VPN\KSOS 21.26 (MR26) & KES 14...
harlan4096 — 11:58
Adobe Acrobat Reader DC 2026.001.21483
Adobe Acrobat Read...harlan4096 — 11:56
Microsoft Edge 147.0.3912.86
Version 147.0.3912...harlan4096 — 11:55
AMD EXPO 1.2 now available, adds partial...
1usmus reveals AMD...harlan4096 — 11:40
Microsoft Rolls Out Windows Update to Re...
Microsoft is rolli...harlan4096 — 11:36

[-]
Birthdays
Today's Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
Upcoming Birthdays
avatar (51)Toligo

[-]
Online Staff
There are no staff members currently online.

>