Tag: South Korean software

Lazarus Hits 6 South Korean Firms via Cross EX, Innorix Flaws and ThreatNeedle Malware
News

Lazarus Hits 6 South Korean Firms via Cross EX, Innorix Flaws and ThreatNeedle Malware

In a campaign known as Operation SyncHole, the well-known Lazarus Group, which has ties to North Korea, has targeted at least six South Korean institutions. According to a Kaspersky study released today, the activity targeted South Korea's financial, software, IT, semiconductor manufacturing, and telecommunications sectors. In November 2024, the first indication of compromise was discovered. According to security researchers Sojun Ryu and Vasily Berdnikov, the operation combined a clever watering hole tactic with exploiting vulnerabilities in South Korean software. Lateral movement was also accomplished by exploiting a one-day vulnerability in Innorix Agent. Variants of well-known Lazarus tools, including ThreatNeedle, AGAMEMNON, wAgent, SIGNBT, and COPPERHEDGE, have been seen to...