Operation SyncHole: Lazarus Escalates Cyberattacks Against South Korean Industries
The Lazarus group has launched a stealthy campaign, “Operation SyncHole,” targeting South Korean industries with a mix of software exploits, watering hole attacks, and lateral movement techniques. By compromising trusted local software like Cross EX and Innorix Agent, the attackers slipped malware such as ThreatNeedle, SIGNBT, and COPPERHEDGE into corporate networks, aiming to dig deep into internal systems. Using clever tricks like DLL sideloading, fake websites, and even a downloader named Agamemnon, they blended into trusted environments. This operation shows how Lazarus continues to sharpen its tactics, quietly evolving tools while targeting supply chains to maximize damage.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox