RL Blog

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabs
ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
Security OperationsMarch 9, 2023

The Week in Security: Lazarus attacks same South Korean entity twice, use of hard-coded secrets is up

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

Carolynn van Arsdale, Writer, ReversingLabs.Carolynn van Arsdale
FacebookFacebookXX / Twitter
LinkedIn
LinkedIn
blueskyBluesky
Email Us

Main Story

IntroLazarus hacking group rises after new details emerge from its latest attack on a South Korean financial orgHard-coded secrets are up 67% as secrets sprawl threatens software supply chain (CSO)Israel blames prolific Iranian-linked hacking group for February university hack (Cyberscoop)Emotet malware attacks return after three-month hiatus (BleepingComputer)Darktrace warns of rise in AI-enhanced scams since ChatGPT release (The Guardian)New TPM 2.0 flaws could let hackers steal cryptographic keys (BleepingComputer)

This week: North Korean-linked hacking group Lazarus attacked the same South Korean financial entity twice in 2022. Also: The number of hard-coded secrets is way up.

This Week’s Top Story

Lazarus hacking group rises after new details emerge from its latest attack on a South Korean financial org

According to The Hacker News, Lazarus, a North Korean-linked hacking group, attacked the same financial business entity in South Korea twice in 2022. Lazarus first attacked the organization in May 2022 by exploiting a vulnerable version of a certificate software, used widely by public entities and universities. In the hacking group’s latest attack, occurring in October 2022, Lazarus exploited a zero-day in the same software program.

AhnLab Security Emergency Response Center (ASEC), the firm that discovered both attacks, has not yet disclosed the exploited software, since “the vulnerability has not been fully verified,” ASEC said in an update. In the latest attack, hackers were able to gain access to the system (so far, it is unknown how they did this), and then abused the zero-day bug, allowing them to perform lateral movement. Lazarus then used a Bring Your Own Vulnerable Driver (BYOVD) attack to disable the AhnLab V3 anti-malware engine, which the group has used in prior attacks according to AhnLab and ESET, another cybersecurity firm.

Lazarus also attempted to evade detection by changing file names before deleting them, as well as modifying timestamps using timestomping, an anti-forensic technique. This latest attack also allowed the hacking group to deliver multiple backdoor payloads designed to connect to a remote command-and-control (C2) server, allowing Lazarus to retrieve additional binaries and execute them in a fileless manner.

According to ASEC, Lazarus is a capable threat actor that continually researches software vulnerabilities and changes their TTPs (Techniques, Tactics and Procedures). They do this by “altering the way they disable security products and carry out anti-forensic techniques,” allowing the group to interfere with or delay any detection and analysis. Based on the hacking group’s willingness to exploit new vulnerabilities, it’s likely that they could carry out more attacks in South Korea and elsewhere.

News Roundup

Here are the stories we’re paying attention to this week…

Hard-coded secrets are up 67% as secrets sprawl threatens software supply chain (CSO)

According to GitGuardian’s State of Secrets Sprawl 2023 report, the number of detected hard-coded secrets increased by 67% last year compared to 2021, with 10 million new secrets discovered in public GitHub commits in 2022.

Israel blames prolific Iranian-linked hacking group for February university hack (Cyberscoop)

A prolific hacking group known as MuddyWater, which is affiliated with the Iranian government, is responsible for the Feb. 11 cyberattack on Technion University in Israel, the Israeli government said this past Tuesday.

Emotet malware attacks return after three-month hiatus (BleepingComputer)

Emotet is a notorious malware distributed through email containing malicious Microsoft Word and Excel document attachments. When users open these documents and macros are enabled, the Emotet DLL will be downloaded and loaded into memory.

Darktrace warns of rise in AI-enhanced scams since ChatGPT release (The Guardian)

The cybersecurity firm Darktrace has warned that since the release of ChatGPT it has seen an increase in criminals using artificial intelligence to create more sophisticated scams to con employees and hack into businesses.

New TPM 2.0 flaws could let hackers steal cryptographic keys (BleepingComputer)

The Trusted Platform Module (TPM) 2.0 specification is affected by two buffer overflow vulnerabilities that could allow attackers to access or overwrite sensitive data, such as cryptographic keys.

Tags:Security Operations

More Blog Posts

Main Story

IntroLazarus hacking group rises after new details emerge from its latest attack on a South Korean financial orgHard-coded secrets are up 67% as secrets sprawl threatens software supply chain (CSO)Israel blames prolific Iranian-linked hacking group for February university hack (Cyberscoop)Emotet malware attacks return after three-month hiatus (BleepingComputer)Darktrace warns of rise in AI-enhanced scams since ChatGPT release (The Guardian)New TPM 2.0 flaws could let hackers steal cryptographic keys (BleepingComputer)

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagram

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

smiling woman with glasses
The Week in Security: Lazarus attacks same South Korean entity twice, use of hard-coded secrets is up

Keep learning

  • Get up to speed on the agentic SOC in this webinar: Autonomy, Not Autopilot: Talking Agentic SOC. Plus: Learn about the new Agentic SOC Alliance.
  • Get all of RL's malware analysis and threat hunting updates with this H1 product update post — and join the webinar to discuss what a modern SOC looks like.
  • Get on top of Malware-as-a-Service with RL's report, "Copy, Paste, Compromise: The Tale of ClickFix" — and grab the related YARA rule.
  • Read this customer story about a leading AI company using RL threat intelligence.
  • Learn how to build high-fidelity threat intel feeds for Agentic AI in this webinar.
  • Take a deep dive into suspicious file triage and best practices in this whitepaper.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence

Instagram
YouTubeYouTube
blueskyBluesky
for reputation data and intelligence.

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research

Related

AI use in cybersecurity is on the rise — and so is burnoutCan AI beat AI? 3 challenges with VulnOps adoptionWorking with agentic AI: A SecOps survival guide
AI secops burnout

AI use in cybersecurity is on the rise — and so is burnout

The Life and Times of Cybersecurity Professionals study highlights a trend that has accelerated as cyber has become more complex.

Learn More about AI use in cybersecurity is on the rise — and so is burnout
AI use in cybersecurity is on the rise — and so is burnout
AI vs AI robots

Can AI beat AI? 3 challenges with VulnOps adoption

SecOps leaders must tackle cost and risk to deliver autonomous vulnerability operations. But with frontier AI, it's critical.

Learn More about Can AI beat AI? 3 challenges with VulnOps adoption
Can AI beat AI? 3 challenges with VulnOps adoption
SecOps and AI

Working with agentic AI: A SecOps survival guide

Agentic AI will disrupt how SOC teams are built — and the way CISOs hire. Here’s how to embrace AI.

Learn More about Working with agentic AI: A SecOps survival guide
Working with agentic AI: A SecOps survival guide