• Latest
  • Trending
  • All
  • Industry
  • Compliance
  • Global Trade
  • Industry
  • Sustainability & Ethics
  • Video
  • Security & Risk
A screen shot showcasing the red face on a computer screen, possibly indicating malware or a Log4j vulnerability.

Lazarus Group Utilizes Log4j Vulnerability to Deploy New Malware

12/11/2023
CTW Saudi Arabia Returns for Its 3rd Edition, Unlocking Global Business Opportunities

CTW Saudi Arabia Returns for Its 3rd Edition, Unlocking Global Business Opportunities

11/13/2025
Gulf 4P 2025 to Power Regional Growth in Plastics, Packaging, Printing, and Petrochemicals

Gulf 4P 2025 to Power Regional Growth in Plastics, Packaging, Printing, and Petrochemicals

11/13/2025
Grew Energy Private Limited Named Finalist for Solar Energy Manufacturer of the Year at Go Global Awards

Grew Energy Private Limited Named Finalist for Solar Energy Manufacturer of the Year at Go Global Awards

11/13/2025
Innovative Filtrex Techno Engineering India Private Limited Named Finalist in Filtration Technology Innovator Category at the 2025 Go Global Awards

Innovative Filtrex Techno Engineering India Private Limited Named Finalist in Filtration Technology Innovator Category at the 2025 Go Global Awards

11/13/2025
Rich Freight Services Ltd Named Finalist for “Project Cargo Specialists of the Year” at the 2025 Go Global Awards

Rich Freight Services Ltd Named Finalist for “Project Cargo Specialists of the Year” at the 2025 Go Global Awards

11/12/2025
The Allied Founders Pvt Ltd Named Finalist for Carbon-Neutral Exporter of the Year at the 2025 Go Global Awards

The Allied Founders Pvt Ltd Named Finalist for Carbon-Neutral Exporter of the Year at the 2025 Go Global Awards

11/12/2025
Vidushi Infotech SSP Pvt. Ltd. Named Finalist in Digital Trade Pioneer Category at the 2025 Go Global Awards

Vidushi Infotech SSP Pvt. Ltd. Named Finalist in Digital Trade Pioneer Category at the 2025 Go Global Awards

11/07/2025
Cellomatics Biosciences Named Finalist for Bioscience Innovator of the Year at the 2025 Go Global Awards

Cellomatics Biosciences Named Finalist for Bioscience Innovator of the Year at the 2025 Go Global Awards

11/07/2025
Amel International Services Limited Named Finalist for Outstanding Innovation in Food Processing at Go Global Awards

Amel International Services Limited Named Finalist for Outstanding Innovation in Food Processing at Go Global Awards

11/07/2025
HirtProductions (Company in Formation) Named Go Global Awards Finalist in Film Visionary Category

HirtProductions (Company in Formation) Named Go Global Awards Finalist in Film Visionary Category

11/07/2025
Ecom Global Systems Named Go Global Awards Finalist in eCommerce Fulfillment Provider of the Year Category

Ecom Global Systems Named Go Global Awards Finalist in eCommerce Fulfillment Provider of the Year Category

11/07/2025
Portlink Ghana Limited Named Finalist in African Logistics Excellence at the Go Global Awards

Portlink Ghana Limited Named Finalist in African Logistics Excellence at the Go Global Awards

11/06/2025
supplychainreport
Friday, November 14, 2025
  • Home
  • Industry
    • Supply Chain
    • Logistics & Transportation
    • Importing & Exporting
    • Manufacturing
    • Warehousing & Distribution
  • Compliance
    • Supply Chain Transparency
    • Anti-Money Laundering (AML)
    • Know Your Customer (KYC)
    • Risk Management
    • Export Controls
    • Sanctions
  • Global Trade
    • Market Trends
    • Economic Indicators
    • Sourcing
    • Trade Policies
    • International Relations
    • Trade Agreements
    • Tariffs & Duties
    • Import/Export Statistics
  • Luxury Goods
  • Industry
    • Blockchain in Supply Chain
    • Importing & Exporting
    • Automation & Robotics
    • Artificial Intelligence in Trade
    • Data & Analytics
  • Sustainability & Ethics
    • Green Supply Chains
    • Sustainable Logistics
    • Ethical Sourcing
    • Corporate Social Responsibility
    • Environmental Policies
  • Security & Risk
    • Cybersecurity in Trade
    • Fraud & Scams
    • Risk Mitigation
    • Security Protocols
    • Data Protection
  • ITC News
    • ITC Featured Members
    • ITC Business Councils Highlights
  • Events
    • Upcoming Conferences
    • Upcoming FREE Educational Webinars
No Result
View All Result
supplychainreport
No Result
View All Result

Lazarus Group Utilizes Log4j Vulnerability to Deploy New Malware

by Richie
12/11/2023
in Cybersecurity in Trade, Security & Risk

YOU MAY ALSO LIKE

Merchant International Systems Ltd Nominated for 2025 Go Global Awards in London

Merchant International Systems Limited Recognized for Excellence in Safety and Technology Solutions

The Lazarus hacking group, known for its origins in North Korea, continues to exploit the CVE-2021-44228 vulnerability, commonly referred to as “Log4Shell.” Their latest campaign involves the deployment of three new malware types, all developed using the D programming language, a choice likely made to evade detection due to its rarity in cybercrime.

This campaign, dubbed “Operation Blacksmith” by Cisco Talos researchers, began around March 2023 and primarily targets companies in the manufacturing, agriculture, and physical security sectors across the globe. This operation marks a significant evolution in Lazarus’s tactics and tools.

New Malware Deployed The first of the new malware, NineRAT, is a remote access trojan (RAT) that utilizes the Telegram API for command and control (C2) communications. It is capable of executing a variety of commands received through Telegram, including gathering system information, file exfiltration, and updating or uninstalling itself.

NineRAT also features a dropper component for establishing persistence and launching its main binaries on infected systems.

The second malware, DLRAT, serves as both a trojan and a downloader. It begins by collecting and sending preliminary system information to the C2 server. It then awaits further commands, which can include file download and upload, system file manipulation, and entering a dormant state.

The third component discovered is BottomLoader, a malware downloader. It fetches and executes payloads from a specified URL using PowerShell, also modifying the Startup directory for persistence. BottomLoader can exfiltrate files from the infected system to the C2 server.

Exploiting Log4Shell Vulnerability Lazarus leverages the Log4Shell vulnerability to conduct these attacks, primarily targeting VMWare Horizon servers with the outdated Log4j logging library. This allows remote code execution on the servers. Once compromised, Lazarus establishes persistent access, conducts reconnaissance, creates new admin accounts, and deploys credential-stealing tools like ProcDump and MimiKatz.

In a second phase, NineRAT is deployed, providing a wide range of functionalities. Cisco Talos suggests that Lazarus might be sharing the collected data with other advanced persistent threat (APT) groups under their umbrella, based on observed system re-fingerprinting activities, which imply data collection for multiple actors.

This ongoing situation highlights the continued security risks posed by unpatched vulnerabilities like Log4Shell and the evolving nature of cyber threats from groups like Lazarus.

Find the latest supply chain report news at The Supply Chain Report. For international trade tools, see ADAMftd.com.

#LazarusGroup #CyberSecurity #Log4Shell #CVE2021 #OperationBlacksmith #Malware #NineRAT #DLRAT #BottomLoader #CiscoTalos #VMWare #CyberThreats #APT

ShareTweet

Subscribe Our Newsletter

Share Your News

Whether it’s a groundbreaking achievement, a heartwarming tale, or an insightful perspective, we want to hear it. Share your news with us, and let’s amplify your voice in the digital symphony of stories.

Submit

A man is riding a bike on a hill.

The Supply Chain Report is your essential daily news website, serving as a trusted source for comprehensive coverage of the complex and ever-evolving global supply chain dynamics. Our expert team delves into the intricacies of international trade, manufacturing, logistics, importing, exporting, and supply chain management; providing in-depth analysis and up-to-date news on the latest trends, disruptions, and technological advancements affecting industries worldwide. From detailed reports on international trade through to insights into procurement strategies and inventory management, we offer valuable content that helps professionals stay informed and make knowledgeable decisions in a fast-paced market.

Each day, we bring you cutting-edge news and expert commentary that dissect significant international trade and supply chain issues Our coverage spans a wide array of sectors including manufacturing, retail, healthcare, food, consumer goods, and technology, ensuring that no matter your field, you have the strategic information needed to navigate the challenges and opportunities of today’s supply chain landscape. By synthesizing complex data and presenting actionable insights, The Supply Chain Report empowers business leaders, policymakers, and logistics professionals to optimize their operations and drive forward with confidence in an interconnected world.

Connect With Us

  • About
  • Events
  • Privacy Policy
  • Contact Us

© 2024 International Centre for Trade Transparency Limited. Incorporated in the United Kingdom.

No Result
View All Result
  • Home
  • Industry
    • Supply Chain
    • Logistics & Transportation
    • Importing & Exporting
    • Manufacturing
    • Warehousing & Distribution
  • Compliance
    • Supply Chain Transparency
    • Anti-Money Laundering (AML)
    • Know Your Customer (KYC)
    • Risk Management
    • Export Controls
    • Sanctions
  • Global Trade
    • Market Trends
    • Economic Indicators
    • Sourcing
    • Trade Policies
    • International Relations
    • Trade Agreements
    • Tariffs & Duties
    • Import/Export Statistics
  • Luxury Goods
  • Industry
    • Blockchain in Supply Chain
    • Importing & Exporting
    • Automation & Robotics
    • Artificial Intelligence in Trade
    • Data & Analytics
  • Sustainability & Ethics
    • Green Supply Chains
    • Sustainable Logistics
    • Ethical Sourcing
    • Corporate Social Responsibility
    • Environmental Policies
  • Security & Risk
    • Cybersecurity in Trade
    • Fraud & Scams
    • Risk Mitigation
    • Security Protocols
    • Data Protection
  • ITC News
    • ITC Featured Members
    • ITC Business Councils Highlights
  • Events
    • Upcoming Conferences
    • Upcoming FREE Educational Webinars

© 2024 International Centre for Trade Transparency Limited. Incorporated in the United Kingdom.