Researchers linked a targeted malware campaign to the Lazarus Group after attackers distributed malicious Microsoft Word files masquerading as Korean job postings, including a fake Cisco Korea systems engineer listing. The lure documents, including "Job Description.doc" and "Job Descriptions.doc", used heavily obfuscated VBA macros that required victims to enable macros before dropping a PE32 payload named jusched.exe, disguised as Java Update Scheduler, into %APPDATA%\Roaming. The documents also displayed a decoy job description to reduce suspicion while the malware executed in the background.
Analysis from ESRC and Cisco Talos found the malware used an XOR 0xE7 decryption routine, similar macro obfuscation, and reused command construction techniques previously seen in earlier Lazarus operations. The payload attempted to contact compromised legitimate websites over HTTP, including secuvision.co.kr, to retrieve follow-on commands or second-stage malware. Investigators tied the activity to prior Lazarus campaigns such as Operation Arabian Night, Coin Manager, and related 2017 job-themed intrusions, indicating a sustained pattern of using employment lures and compromised websites to gain initial access to targeted organizations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
ESRC reported discovering the malicious Word document "Job Description.doc" and identified the activity as a Lazarus Group campaign it named "Operation Extreme Job." The lure was distributed via a Korean website associated with IP camera or CCTV sales and dropped jusched.exe plus a decoy job-description file if macros were enabled.
ESRC said the Lazarus-linked lure document was created around 9 p.m. on January 29, 2019, and the dropped malware was built at 2019-01-29 21:00:47 KST. The files were prepared as part of the campaign later named Operation Extreme Job.
Talos observed another related campaign using the filename "이력서_자기소개서.xls" as a lure. The November 2017 document used the same macro execution method and XOR key and contacted ilovesvc.com after dropping another PE32 executable.
Talos reported a related campaign using a ZIP archive named "주요 IT 정보보호 및 보안 업체 리스트.zip" containing an Office document. The sample used the same macros, XOR 0xe7 key, and dropped a PE32 file named jusched.exe while communicating with syadplus.com.
ESRC referenced a spear-phishing attack on a well-known Korean computer security company that used an HWP exploit instead of Office macros. The attack reportedly dropped jusched.exe, created a jusched.lnk startup shortcut, and reused C2 paths on ilovesvc.com and syadplus.com.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.