The Lazarus Group ran a spearphishing campaign that delivered malicious Microsoft Word documents to targets in aerospace, defense, research, and financial sectors, including organizations linked to Boeing, BAE Systems, Lockheed Martin, and the Republic of Korea Army. The infection chain used remote template injection to fetch an external DOTM file, whose macro dropped a lure document and a malicious DLL such as onenote.db into the victim’s AppData path, then executed the implant while showing a decoy file to reduce suspicion. Related reporting describes similar Lazarus lures sent in spoofed emails, with separate payloads for 32-bit and 64-bit systems and reconnaissance-focused first-stage malware.
The implant executed through rundll32.exe and established persistence via the Windows Startup folder, techniques widely tracked in MITRE ATT&CK as T1218.011 and T1547.001. Once active, it collected host, process, and disk information, compressed or encrypted the data, and exfiltrated it over HTTP POST using compromised or attacker-controlled infrastructure, including IIS/Plesk-hosted domains such as elite4print.com and astedams.it. Analysts linked the activity to Lazarus based on recurring tradecraft, lure themes, victim profiling, and overlap with operations such as Operation Dream Job, where the group similarly abused rundll32.exe and autostart mechanisms for stealthy execution and persistence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On January 27, 2022, Malwarebytes Labs described Lazarus-linked malware that used a Startup-folder shortcut named windowsupdateconf.lnk to launch wuauclt.exe with unusual arguments and load a malicious wuaueng.dll. The DLL contained an embedded payload for command-and-control activity, marking a new execution and persistence technique distinct from the earlier rundll32-based campaigns.
On January 18, 2022, Malwarebytes observed a Lazarus spear-phishing campaign using Lockheed Martin job lures in which the malware retrieved modules embedded in PNG files from a GitHub repository and exfiltrated results back via HTTP PUT. The report said this was the first time the researchers had seen Lazarus leverage GitHub as C2 in this way.
The analyzed sqlite3 component embedded in the later Lazarus implant corresponded to a SQLite source ID dated 2020-01-27 19:55:54. This provides a concrete technical timestamp for a component used in the malware.
The analysis identified elite4print.com and astedams.it as command-and-control domains hosted on Windows IIS/Plesk infrastructure and attributed the campaign to Lazarus. The attribution was based on recurring tradecraft, lure themes, targeting, and campaign clustering.
The DLL implant established persistence via the Windows Startup folder, gathered host, process, and disk information, and exfiltrated data to command-and-control servers over HTTP POST using a Mozilla-like user agent. It also used rundll32 and thread creation as part of execution.
The 2020 infection chain fetched an external DOTM template, whose macro extracted a decoy document and an architecture-specific DLL saved as onenote.db under the victim's AppData path. The macro loaded the DLL, invoked its export, opened the lure document, and quit the original file.
A later Lazarus spear-phishing campaign used remote template injection in malicious Word documents to deliver a DLL-based implant against targets including Boeing DSS, Boeing PMS, BAE/Lockheed Martin, and the Republic of Korea Army. Victim identifiers embedded in the malware were mapped to those organizations in the analysis.
The campaign's backend VBScript on compromised websites profiled victims and used whitelist and blacklist logic to decide whether to deliver a second-stage TorisMa payload or a decoy Doris payload. Selection was based on victim IP hashes and collected system information.
The first-stage implant created a Startup-folder shortcut named thumbnail.lnk that launched rundll32.exe with the dropped DLL and its export, enabling persistence at logon. The implant then performed reconnaissance and beaconed to command and control over HTTP POST.
A Lazarus-attributed spear-phishing campaign used spoofed emails with malicious Microsoft Word documents to infect victims. The documents dropped a DLL disguised as a database file, executed it via macros, and displayed a decoy document to the user.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cyberandramen.net
Open sourceblog.malwarebytes.com
Open sourcegithub.com
Open sourcetelsy.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.