Lazarus Hackers are Using Log4j to Hack US Energy Companies

Share:

A new cyber espionage campaign targeting US, Canadian, and Japanese energy providers has been linked to the North Korean state-sponsored Lazarus hacking group, according to security researchers.

Cisco Talos, a threat intelligence company, announced Thursday that Lazarus, also known as APT38, was observed targeting unidentified energy providers in the United States, Canada, and Japan between February and July of this year.

According to Cisco’s findings, the hackers exploited a year-old Log4j vulnerability known as Log4Shell to compromise internet-exposed VMware Horizon servers in order to gain an initial foothold on a victim’s enterprise network before deploying bespoke malware known as “VSingle” and “YamaBot” to gain long-term persistent access.

Japan’s national cyber emergency response team, known as CERT, recently linked YamaBot to the Lazarus APT. Symantec first disclosed information of this espionage campaign in April of this year, attributing the operation to “Stonefly,” another North Korean hacking group with some overlaps with Lazarus.

However, Cisco Talos discovered a previously unknown remote access trojan (RAT) called “MagicRAT,” which is attributed to the Lazarus Group and is used by hackers for reconnaissance and credential theft.

Talos researchers Jung soo An, Asheer Malhotra, and Vitor Ventura, “The main goal of these attacks was likely to establish long-term access into victim networks to conduct espionage operations in support of North Korean government objectives. This activity aligns with historical Lazarus intrusions targeting critical infrastructure and energy companies to establish long-term access to siphon off proprietary intellectual property.”

However, in recent months, the group has shifted its focus to blockchain and cryptocurrency organisations. It has been associated with the recent thefts of $100 million in cryptocurrency from Harmony’s Horizon Bridge and $625 million in cryptocurrency from the Ronin Network, an Ethereum-based sidechain created for the popular play-to-earn game Axie Infinity.

Pyongyang has long used stolen cryptocurrency and information theft to finance its nuclear weapons programme. In July, the United States offered a $10 million reward for data on members of state-sponsored North Korean threat groups, including Lazarus, more than doubling the amount previously offered. The State Department made the announcement in April.

The Lazarus Group is a North Korean-backed hacking organisation best known for the high-profile Sony hack in 2016 and the WannaCry ransomware attack in 2017. Lazarus is also motivated by efforts to support North Korea’s state objectives, such as military R&D and evasion of international sanctions.

https://www.cysecurity.news/2022/09/lazarus-hackers-are-using-log4j-to-hack.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:09 pm, Jul 8, 2025
weather icon 23°C
L: 22° | H: 25°
clear sky
Humidity: 38 %
Pressure: 1018 mb
Wind: 8 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:53 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
22° | 25°°C 0 mm 0% 7 mph 40 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 26°°C 0.16 mm 16% 8 mph 58 % 1022 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 11 mph 76 % 1024 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 8 mph 65 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 10 mph 65 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
23° | 23°°C 0 mm 0% 7 mph 38 % 1017 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 7 mph 35 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 20°°C 0 mm 0% 4 mph 40 % 1018 mb 0 mm/h
Tomorrow 1:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 50 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 4 mph 58 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
16° | 16°°C 0 mm 0% 4 mph 51 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
21° | 21°°C 0 mm 0% 6 mph 58 % 1022 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 56 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,987.25
0.49%
Ethereum(ETH)
€2,206.70
0.95%
Tether(USDT)
€0.85
0.02%
XRP(XRP)
€1.95
-1.46%
Solana(SOL)
€129.57
-0.57%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145524
0.24%
Shiba Inu(SHIB)
€0.000010
0.92%
Pepe(PEPE)
€0.000009
0.68%
Scroll to Top