Palo Alto Networks Unit 42 reported a sustained spearphishing campaign linked to the Lazarus group that targeted Korean-speaking individuals and later people associated with U.S. defense contractors. The attackers used weaponized Microsoft Office documents with malicious VBA macros, first relying on Korean-language decoys and later shifting to English-language job descriptions and internal policy material tied to defense firms. Researchers said the activity remained active through mid-2017 and showed little operational change despite earlier public exposure.
The malware and delivery chain shared multiple traits with Operation Blockbuster and the later Blockbuster Sequel, including packed payloads, fake TLS-like communications, hard-coded command-and-control infrastructure, encoded strings, cleanup batch scripts, direct IP beaconing, and overlapping macros, XOR keys, and infrastructure. Unit 42 also found reused compromised hosts serving lure files, metadata such as the author name ISkyISea, and evidence of an automated document weaponization process, leading researchers to assess that the operators were either the same Lazarus-linked actors or closely cooperating with them.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported that the intrusion campaign remained active through July 2017 and had shifted decoy themes to English-language job descriptions and internal policy material from U.S. defense contractors.
A malicious file named "한싹시스템.doc" was submitted to VirusTotal as part of the spearphishing campaign Unit 42 investigated.
The unpacked payload with SHA256 032ccd6ae0a6e49ac93b7bd10c7d249f853fff3f5771a1fe3797f733f09db5a0 carried a compile timestamp of March 2, 2017.
Based on overlaps in tools, payloads, macros, XOR keys, infrastructure, and command-and-control behavior, Unit 42 assessed the operators were the same group behind or closely cooperating with the actors from Operation Blockbuster Sequel and ultimately Operation Blockbuster.
After the earlier Korean-language lure activity, Unit 42 discovered continued intrusion activity targeting individuals associated with United States defense contractors using weaponized Office documents.
By pivoting on reused macro logic and variable names, Unit 42 found additional malicious documents and testing files, suggesting an automated document weaponization process and possible English-speaking involvement.
Unit 42 analyzed a 2017 campaign using malicious Word documents with VBA macros targeting Korean-speaking individuals and attributed it to Lazarus based on overlaps in malware code, infrastructure, and protocol behavior.
Unit 42 referenced the 2014 Sony Pictures Entertainment attack as prior activity tied to the Lazarus group in its attribution discussion.
Unit 42 cited the 2013 DarkSeoul attacks as earlier operations associated with the Lazarus group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.