The notorious North Korean threat group Lazarus has executed a sophisticated espionage campaign against multiple South Korean organizations across software, IT, finance, telecommunications, and semiconductor manufacturing sectors. Dubbed “Operation SyncHole” by Kaspersky researchers, the attack compromised at least six organizations between November 2024 and February 2025, with researchers suspecting many more victims due to the widespread use of the exploited software.
## Attack Methodology
The campaign employed a multi-stage approach:
1. **Initial Access**: Hackers compromised legitimate South Korean media portals with server-side scripts that profiled visitors and redirected suitable targets to malicious domains.
2. **Exploitation**: Victims were directed to fake websites mimicking software vendors, particularly the distributor of Cross EX—a tool required by South Koreans for online banking and government interactions. A malicious JavaScript exploited vulnerabilities in Cross EX to deliver malware.
3. **Execution**: The exploit launched the legitimate ‘SyncHost.exe’ process and injected shellcode to load the ‘ThreatNeedle’ backdoor, capable of executing 37 different commands on infected hosts.
## Multiple Infection Chains
Kaspersky observed various attack paths across the six confirmed victims:
– In the first phase, ThreatNeedle deployed ‘LPEClient’ for system profiling, ‘wAgent’ or ‘Agamemnon’ malware downloaders, and ‘Innorix Abuser’ for lateral movement.
– In some cases, Lazarus bypassed ThreatNeedle entirely, using the ‘SIGNBT’ implant to deploy the ‘Copperhedge’ backdoor for internal reconnaissance.
The ‘Innorix Abuser’ tool exploited a vulnerability in the Innorix Agent file transfer solution (version 9.2.18.496), which has since been patched.
## Attribution and Evolution
Kaspersky confidently attributed the campaign to Lazarus based on:
– Tooling used in the attacks
– Working hours/timezone patterns
– Techniques, tactics, and procedures specific to the group
Researchers noted that Lazarus is evolving toward more lightweight, modular tools that offer improved stealth and configurability.
During their investigation, Kaspersky also discovered an unrelated zero-day vulnerability (KVE-2024-0014) in Innorix Agent that allowed arbitrary file downloads. This flaw has since been patched following responsible disclosure through KrCERT.
