Lazarus Research
This repository publishes analysis reports and analysis tools for Operation Dream Job and Operation JTrack for Lazarus.
Tools
Python tools for analyzing malware.
blindingcan_rc4_post_decode.py
Python script to decode URL parameter for BLINDINGCAN_RC4.
blindingcan_aes_post_decode.py
Python to decode POST data for BLINDINGCAN_AES.
Research results
Slides
-
Hitcon 2021
-
CODE BLUE 2021
TTPs
- MITRE ATT&CK® Mapping for Lazarus Group