Andariel Group injects malicious scripts into compromised South Korean websites and collects ActiveX object information before they are to use their exploit. The group is part of well-known notorious Lazarus Group. The new script contains two additional ActiveX objects related to Digital Rights Management and voice conversion software. Researchers believe that new script was trying to collect the different ActiveX. object and that could be for their next targets for a watering hole exploit attack. Researchers from Trend Micro published a blog post with analysis report and comparison between the previous and new script.”]
Source: https://gbhackers.com/andariel-group-new-reconnaissance/