Malwarebytes says the Lazarus group with ties to North Korea used a new weapon in a recent phishing campaign targeting South Koreans. The malware embedded in the images drops two payloads, and the actual attack takes place after the second has been downloaded. The attack was initiated with a series of phishing emails that contained a malicious Microsoft Word document named “Application Form,” which purported to be a form submitted by someone to host a fair in a South Korean city. The attackers hoped to temporarily confuse the victim as the malware then took several actions, including retrieving and decompressing the malware.”]
Source: https://www.bankinfosecurity.com/lazarus-hiding-rats-in-bmp-images-a-16438

