image credit: Adobe Stock

Lazarus Group Exploits Zero-Day Vulnerability to Hack South Korean Financial Entity

March 8, 2023

The North Korea-linked Lazarus Group has been observed weaponizing flaws in an undisclosed software to breach a financial business entity in South Korea twice within a span of a year.

While the first attack in May 2022 entailed the use of a vulnerable version of a certificate software that’s widely used by public institutions and universities, the re-infiltration in October 2022 involved the exploitation of a zero-day in the same program.

Cybersecurity firm AhnLab Security Emergency Response Center (ASEC) said it’s refraining from mentioning the software owing to the fact that “the vulnerability has not been fully verified yet and a software patch has not been released.”

Read More on The Hacker News