{"id":19460,"date":"2022-04-12T09:02:11","date_gmt":"2022-04-12T09:02:11","guid":{"rendered":"https:\/\/nsfocusglobal.com\/?p=19460"},"modified":"2026-04-17T18:07:44","modified_gmt":"2026-04-17T18:07:44","slug":"apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users","status":"publish","type":"post","link":"https:\/\/nsfocusglobal.com\/pt-br\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/","title":{"rendered":"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p>Recently, NSFOCUS Security Labs captured a series of phishing documents containing specific Korean bait information. Most of these documents contain keywords such as &#8220;BTC&#8221;, &#8220;ETH&#8221;, &#8220;NFT&#8221;, and &#8220;account information&#8221;, which trick victims into opening them and then use remote template injection to implant malicious programs, thereby stealing host information. Analysis shows that these phishing documents are linked to the APT group Lazarus and are part of a long-term phishing campaign targeting cryptocurrency users. Further findings in continuous tracking also include that Lazarus reused the attack process in subsequent phishing activities, expanding the attack scope to targets such as the South Korean government and organizations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Event analysis<\/h2>\n\n\n\n<p>In this attack, Lazarus built a type of decoy document containing an &#8220;AhnLab &#8221; icon and prompt information. The prompts for these documents vary, but the common goal is to trick victims into enabling Office&#8217;s document editing capabilities. AhnLab is a cyber security vendor with its headquarters in South Korea. Lazarus uses the name to increase the persuasiveness of the decoy document.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412a.jpg\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412a.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-19461\" width=\"599\" height=\"602\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412a.jpg 798w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412a-298x300.jpg 298w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412a-150x150.jpg 150w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412a-768x773.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412a-230x230.jpg 230w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412a-600x604.jpg 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412a-200x201.jpg 200w\" sizes=\"(max-width: 599px) 100vw, 599px\" \/><\/a><\/figure>\n\n\n\n<p>Another type of decoy document contains Binance icons and related tips. Binance is a cryptocurrency trading platform.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412b.jpg\"><img decoding=\"async\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412b.jpg\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-19463\" width=\"598\" height=\"546\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412b.jpg 797w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412b-300x274.jpg 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412b-768x702.jpg 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412b-600x548.jpg 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2022\/04\/0412b-200x183.jpg 200w\" sizes=\"(max-width: 598px) 100vw, 598px\" \/><\/a><\/figure>\n\n\n\n<p>These phishing documents have different file names, clearly showing that the Lazarus group&#8217;s campaign lasted from the end of March to the beginning of April, and the main targets of the attack were cryptocurrency followers.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Filename<\/td><td>Translation (English)<\/td><\/tr><tr><td>&iacute;&trade;&bull;&igrave;&cedil;&igrave;&#382;&euml;&pound;&OElig; _20220329.docx<\/td><td>Confirm data_20220329<\/td><\/tr><tr><td>202203_BTC_ETH_&igrave;&para;&rdquo;&ecirc;&deg;&euro;&ecirc;&sup3;&bdquo;&igrave;&nbsp;&bull;&igrave;&nbsp;&bull;&euml;&sup3;&acute;<\/td><td>202203_BTC_ETH_Other account information<\/td><\/tr><tr><td>202203_BTC_ETH_&igrave;&#382;&euml;&trade;&euml;&sect;&curren;&euml;&sect;&curren;&ecirc;&sup3;&bdquo;&igrave;&nbsp;&bull;&igrave;&nbsp;&bull;&euml;&sup3;&acute;<\/td><td>202203_BTC_ETH_Auto Trading Account Information<\/td><\/tr><tr><td>202204_&igrave;&bull;&rdquo;&iacute;&tilde;&cedil;&iacute;&trade;&rdquo;&iacute;_&iacute;&circ;&not;&igrave;&#382;&ecirc;&cedil;&deg;&iacute;&scaron;.docx<\/td><td>202204_Cryptocurrency_Investment Planning<\/td><\/tr><tr><td>NFT &euml;&para;&bdquo;&iacute;&bull;&nbsp;.docx<\/td><td>NFT allocation<\/td><\/tr><tr><td>Binance_Guide (1).doc<\/td><td>Binance_Tutorial (1)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>This series of malicious documents all contain remote links to obtain subsequent attack payloads by visiting the domain name naveicoipc [.]tech and multiple subdomains under this domain name.<\/p>\n\n\n\n<p>Statistics found that the format of these links used by Lazarus this time is similar, including the fixed domain name naveicoipc [.]tech, subdomain composed of random characters, the root directory ACMS\/, secondary directory composed of random characters, the file name including &#8220;Accounts&#8221; or &#8220;Template&#8221; character, and the ID parameter composed of random characters. An example link is: http:\/\/naveicoipc[.]tech\/ACMS\/0Mogk1Cs\/topAccounts?uid=3490blxl<\/p>\n\n\n\n<p>As the event progressed, Lazarus began to adjust the decoy form, expanding the target of this attack to the South Korean government and organizations.<\/p>\n\n\n\n<p>In the decoys delivered in the post-stage, Lazarus started using the following filenames:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Filename<\/td><td>Translation (English)<\/td><\/tr><tr><td>&igrave;&oelig;&nbsp;&igrave;&sbquo;&not;&igrave;&circ;&tilde;&igrave;&lsaquo;&nbsp;_&ecirc;&sup3;&nbsp;&igrave;&dagger;&OElig;&igrave;&#382;&yen;.docx<\/td><td>Similar reception_complaint<\/td><\/tr><tr><td>&igrave;&oelig;&nbsp;&igrave;&sbquo;&not;&igrave;&circ;&tilde;&igrave;&lsaquo;&nbsp;&iacute;&ndash;&permil;&igrave;&oelig;&bdquo;&ecirc;&sup3;&nbsp;&igrave;&dagger;&OElig;&igrave;&#382;&yen;.docx<\/td><td>Complaints of similar reception behaviors<\/td><\/tr><tr><td>&igrave;&pound;&frac14;&igrave;&pound;&frac14;&igrave;&acute;&iacute;&scaron;&OElig;&ecirc;&sup2;&deg;&ecirc;&sup3;&frac14;.docx<\/td><td>Shareholders&#8217; meeting results<\/td><\/tr><tr><td>&ecirc;&cedil;&acute;&ecirc;&cedil;&permil;&igrave;&#382;&not;&euml;&sbquo;&oelig;&igrave;&sect;&euro;&igrave;&rsaquo;&ecirc;&cedil;&circ;&igrave;&lsaquo;&nbsp;&igrave;&sup2;&shy;&igrave;&bdquo;&oelig;&igrave;&ndash;&lsquo;&igrave;&lsaquo;.docx<\/td><td>Emergency Disaster Benefit Application Form<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>These file names still contain keywords commonly used by the Lazarus group, which are consistent with the group&#8217;s historical attack targets.<\/p>\n\n\n\n<p>These adjusted malicious documents use the domain name naveicoipg [.]online and its subdomains as remote link addresses for downloading subsequent attack payloads.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Conclusion<\/h1>\n\n\n\n<p>In this Lazarus-linked attack, attackers mass-produced and launched a large number of phishing lures to crucial targets in industries that Lazarus has been paying attention to for a long time. The attack this time seems to be in an exploratory stage because only a part of the domain names in the phishing emails was used in the attack.<\/p>\n\n\n\n<p>NSFOCUS provides the most unique, fresh, and accurate Threat Intelligence in the world. Most available threat feeds have poor visibility into Northern Asia where over 40% of all malicious Internet traffic comes from. NSFOCUS&acirc;&euro;&trade;s Threat Intelligence (NTI) is truly disparate. The NTI helps close this enormous cyber-threat hole with threat intelligence covering APAC and especially North Asia in depth, and gain complete visibility into the global threat landscape. Most of the NTI feeds are analyzed and produced by NSFOCUS&acirc;&euro;&trade;s research team which is more traceable and accurate when compared to open-sourced feeds. Click <a href=\"https:\/\/nsfocusglobal.com\/pt-br\/threat-intelligence-ti-3\/\">here<\/a> for more information on NSFOCUS Threat Intelligence.<\/p>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>Overview Recently, NSFOCUS Security Labs captured a series of phishing documents containing specific Korean bait information. Most of these documents contain keywords such as &#8220;BTC&#8221;, &#8220;ETH&#8221;, &#8220;NFT&#8221;, and &#8220;account information&#8221;, which trick victims into opening them and then use remote template injection to implant malicious programs, thereby stealing host information. Analysis shows that these phishing [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":18525,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[3,5,6],"tags":[62,93,157,489,582,583],"class_list":["post-19460","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-ddos-mitigation","category-emergency-response","tag-ahnlab","tag-apt","tag-cryptocurrency","tag-lazarus","tag-phishing","tag-phishing-email"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users - NSFOCUS<\/title>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users - NSFOCUS\" \/>\n<meta property=\"og:description\" content=\"Overview Recently, NSFOCUS Security Labs captured a series of phishing documents containing specific Korean bait information. Most of these documents\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/\" \/>\n<meta property=\"og:site_name\" content=\"NSFOCUS\" \/>\n<meta property=\"article:published_time\" content=\"2022-04-12T09:02:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-17T18:07:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/09\/data-security-e1632988232729.jpg\" \/>\n<meta name=\"author\" content=\"Jie Ji\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users - NSFOCUS\" \/>\n<meta name=\"twitter:description\" content=\"Overview Recently, NSFOCUS Security Labs captured a series of phishing documents containing specific Korean bait information. Most of these documents\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/09\/data-security-e1632988232729.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jie Ji\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/\"},\"author\":{\"name\":\"Jie Ji\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/person\\\/1077d8fcd7e52c96f17a33b63a0d157b\"},\"headline\":\"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users\",\"datePublished\":\"2022-04-12T09:02:11+00:00\",\"dateModified\":\"2026-04-17T18:07:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/\"},\"wordCount\":802,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/data-security-e1632988232729.jpg\",\"keywords\":[\"AhnLab\",\"APT\",\"Cryptocurrency\",\"Lazarus\",\"Phishing\",\"Phishing Email\"],\"articleSection\":[\"Blog\",\"DDoS Mitigation\",\"Emergency Response\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/\",\"name\":\"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users - NSFOCUS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/data-security-e1632988232729.jpg\",\"datePublished\":\"2022-04-12T09:02:11+00:00\",\"dateModified\":\"2026-04-17T18:07:44+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/data-security-e1632988232729.jpg\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/data-security-e1632988232729.jpg\",\"width\":900,\"height\":383,\"caption\":\"Futuristic skyscrapers with digital network overlay.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nsfocusglobal.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#website\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/\",\"name\":\"NSFOCUS\",\"description\":\"Security Made Smart and Simple\",\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\",\"name\":\"NSFOCUS\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"width\":248,\"height\":36,\"caption\":\"NSFOCUS\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/person\\\/1077d8fcd7e52c96f17a33b63a0d157b\",\"name\":\"Jie Ji\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g\",\"caption\":\"Jie Ji\"},\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/author\\\/jji\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users - NSFOCUS","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"pt_BR","og_type":"article","og_title":"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users - NSFOCUS","og_description":"Overview Recently, NSFOCUS Security Labs captured a series of phishing documents containing specific Korean bait information. Most of these documents","og_url":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/","og_site_name":"NSFOCUS","article_published_time":"2022-04-12T09:02:11+00:00","article_modified_time":"2026-04-17T18:07:44+00:00","og_image":[{"url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/09\/data-security-e1632988232729.jpg","type":"","width":"","height":""}],"author":"Jie Ji","twitter_card":"summary_large_image","twitter_title":"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users - NSFOCUS","twitter_description":"Overview Recently, NSFOCUS Security Labs captured a series of phishing documents containing specific Korean bait information. Most of these documents","twitter_image":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/09\/data-security-e1632988232729.jpg","twitter_misc":{"Escrito por":"Jie Ji","Est. tempo de leitura":"4 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/#article","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/"},"author":{"name":"Jie Ji","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/person\/1077d8fcd7e52c96f17a33b63a0d157b"},"headline":"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users","datePublished":"2022-04-12T09:02:11+00:00","dateModified":"2026-04-17T18:07:44+00:00","mainEntityOfPage":{"@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/"},"wordCount":802,"commentCount":0,"publisher":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization"},"image":{"@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/09\/data-security-e1632988232729.jpg","keywords":["AhnLab","APT","Cryptocurrency","Lazarus","Phishing","Phishing Email"],"articleSection":["Blog","DDoS Mitigation","Emergency Response"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/","url":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/","name":"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users - NSFOCUS","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/#primaryimage"},"image":{"@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/09\/data-security-e1632988232729.jpg","datePublished":"2022-04-12T09:02:11+00:00","dateModified":"2026-04-17T18:07:44+00:00","breadcrumb":{"@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/#primaryimage","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/09\/data-security-e1632988232729.jpg","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2021\/09\/data-security-e1632988232729.jpg","width":900,"height":383,"caption":"Futuristic skyscrapers with digital network overlay."},{"@type":"BreadcrumbList","@id":"https:\/\/nsfocusglobal.com\/apt-group-lazarus-distributing-korean-phishing-lures-to-feel-out-cryptocurrency-users\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nsfocusglobal.com\/"},{"@type":"ListItem","position":2,"name":"APT Group Lazarus Distributing Korean Phishing Lures to Feel Out Cryptocurrency Users"}]},{"@type":"WebSite","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#website","url":"https:\/\/nsfocusglobal.com\/pt-br\/","name":"NSFOCUS","description":"Security Made Smart and Simple","publisher":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nsfocusglobal.com\/pt-br\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization","name":"NSFOCUS","url":"https:\/\/nsfocusglobal.com\/pt-br\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/logo\/image\/","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","width":248,"height":36,"caption":"NSFOCUS"},"image":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/person\/1077d8fcd7e52c96f17a33b63a0d157b","name":"Jie Ji","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/61cb438513c138ce3f1f49e3485f113a0215220de5e284a2bd4e85358f6c8d02?s=96&d=mm&r=g","caption":"Jie Ji"},"url":"https:\/\/nsfocusglobal.com\/pt-br\/author\/jji\/"}]}},"_links":{"self":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/19460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/comments?post=19460"}],"version-history":[{"count":0,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/19460\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media\/18525"}],"wp:attachment":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media?parent=19460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/categories?post=19460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/tags?post=19460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}