Lazarus targeted South Korean organizations through watering-hole attacks and spearphishing, abusing vulnerable local security software including INITECH INISAFE CrossWeb EX and DreamSecurity MagicLine to gain initial access and execute malware. AhnLab linked one 2022 wave to a signed INITECH process, inisafecrosswebexsvc.exe, after a malicious SCSKAppLink.dll was injected to fetch additional payloads from attacker-controlled infrastructure. Across multiple campaigns, victims included defense, finance, media, IT, public-sector, manufacturing, logistics, and pharmaceutical organizations, with reports describing more than 100 incidents and repeated use of compromised Korean websites, IP filtering, staged loaders, DLL side-loading, Windows service abuse, and persistence via the LSA Security Packages registry path.
After compromise, Lazarus deployed backdoors including NukeSped and in some cases escalated to kernel-level evasion using a bring your own vulnerable driver technique. AhnLab said the group abused the signed but vulnerable ene.sys driver, and in some variants Dell's CVE-2021-21551 driver path, to obtain arbitrary kernel memory access and disable security controls in memory, including file and registry callbacks, process and thread monitoring, WFP network filters, and ETW tracing. The activity also involved lateral movement through WMI, and sometimes RDP or SSH, plus credential theft, keylogging, screen capture, SOCKS tunneling, port forwarding, and internal reconnaissance, underscoring a sustained espionage-focused campaign that also created opportunities for supply-chain access and financial theft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
AhnLab published its 'Operation Dream Magic' cyber threat intelligence report attributing a seven-month MagicLine exploitation campaign to Lazarus. The report documented affected sectors, malware families, C2 infrastructure, and recommended upgrading to MagicLine 1.0.0.28.
AhnLab tracked a Lazarus campaign exploiting vulnerable DreamSecurity MagicLine versions from January through July 2023. The operation used compromised South Korean media websites, IP filtering, DLL side-loading, fileless malware, and web-based C2, and resulted in 105 confirmed incidents across 40 organizations.
AhnLab published a report detailing Lazarus watering-hole attacks, exploitation of INISAFECrossWebEX and MagicLine4NX, lateral movement via WMI, RDP, and SSH, and deployment of rootkit malware to neutralize antivirus software. The article also advised patching or removing vulnerable software.
AhnLab published an analysis report on a Lazarus rootkit campaign using BYOVD to abuse the vulnerable ENE Technology driver ene.sys and disable security products. The report also noted variants using Dell's CVE-2021-21551 driver path.
The AhnLab reporting referenced a vulnerability notice for INITECH INISAFE CrossWEB EX V3 dated 2022-07-29. The notice was cited in connection with Lazarus exploitation of vulnerable INITECH software.
AhnLab's analysis noted that the Lazarus rootkit DLL FudModule.dll had a reported compile time of 2022-05-24 12:15:32 UTC. The DLL operated in memory and was used in the BYOVD rootkit chain.
AhnLab published research describing Lazarus malware injected into the legitimate INITECH process inisafecrosswebexsvc.exe and linked SCSKAppLink.dll to broader targeting of major Korean organizations. The report included related malware families, hashes, URLs, and IP indicators.
AhnLab ASEC reported that Lazarus abused INITECH processes for malware infection in April 2022. The intrusion chain began with watering-hole attacks on compromised South Korean websites and expanded into internal networks using vulnerable security software.
AhnLab reported that Lazarus carried out APT attacks in early 2022 against organizations in South Korea's defense, finance, media, and pharmaceutical sectors. The campaign used BYOVD techniques with vulnerable signed drivers to deploy a rootkit and disable security monitoring.
The AhnLab reporting referenced DreamSecurity's vulnerability notice for the MagicLine buffer overflow flaw CVE-2021-26606. The notice date was given as 2021-08-06.
AhnLab reported that Lazarus used the NukeSped backdoor in attacks against South Korean public institutions, universities, and companies in logistics, IT, and manufacturing from around 2020 through 2021. Initial access included spearphishing Word documents with malicious macros and watering-hole attacks exploiting software vulnerabilities.
AhnLab said Symantec published the blog post 'Lazarus Targets Chemical Sector' on April 15, describing Lazarus attacks against the chemical sector. AhnLab linked its own observed malware type to the activity described by Symantec.
AhnLab said 47 companies and institutions, including defense companies, were infected in the first quarter of 2022. Investigators found a malicious DLL, SCSKAppLink.dll, injected into the legitimate INITECH process inisafecrosswebexsvc.exe to download additional malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourcejsac.jpcert.or.jp
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.