The notorious North Korea-linked Lazarus Group has launched a sophisticated cyber campaign dubbed “Operation SyncHole” against at least six South Korean organizations. According to Kaspersky’s recent report, the attacks have targeted companies in software, IT, finance, semiconductor manufacturing, and telecommunications sectors since November 2024.
## Attack Methodology
The campaign combines watering hole attacks with vulnerability exploitation in South Korean software. Victims visiting compromised South Korean media websites are filtered through server-side scripts and redirected to malicious domains. The attackers likely exploit a flaw in Cross EX—legitimate security software widely used in South Korean online banking and government websites—to initiate the infection chain.
Once compromised, the attack proceeds in two phases:
1. Initial access using ThreatNeedle and wAgent malware
2. Persistence establishment with SIGNBT and COPPERHEDGE, enabling reconnaissance and credential theft
## Advanced Techniques
The hackers employed several sophisticated tools:
– LPEClient for victim profiling and payload delivery
– Agamemnon downloader for retrieving additional malware
– Hell’s Gate technique to bypass security solutions
– Exploitation of a zero-day vulnerability in Innorix Agent file transfer tool for lateral movement
Kaspersky researchers discovered and reported an arbitrary file download vulnerability in Innorix Agent, which has since been patched.
## Future Outlook
Kaspersky warns that Lazarus Group’s specialized supply chain attacks targeting South Korea will likely continue. The threat actors are continuously developing new malware and enhancing existing tools to evade detection, particularly by improving command-and-control communication, command structures, and data transmission methods.
