疑似APT-C-26(Lazarus)组织通过加密货币钱包推广信息进行攻击活动分析
2023-01-11 • Qihoo360 • Suspected APT-C-26 (Lazarus) attack activity using cryptocurrency wallet promotional information •
360 Advanced Threat Research Institute describes a suspected APT-C-26/Lazarus campaign delivering a malicious ISO themed around promotion of the Somora cryptocurrency wallet to cryptocurrency holders. The ISO contained wallet screenshots and a malicious “Somora Cryptocurrency Wallet” LNK that invoked PowerShell, dropped a decoy PDF, a loader DLL, and encrypted data, then executed the DLL via rundll32. The loader decrypted shellcode that restored and ran a backdoor assessed as a possible NukeSped variant based on code structure, hardcoded C2 behavior, XOR/base64 command handling, and command-execution logic similar to earlier Lazarus samples. The report lists droidnation[.]net/nation.php and long encrypted/hash artifacts as supporting indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3099980ca44cae6a68887bbcb37ac5e6 | 2023-01-11 | 2023-01-11 |
| HASH | 0ae1172aaca0ed4b63c7c5f5b1739294 | 2023-01-11 | 2023-01-11 |
| DOMAIN | droidnation.net | 2023-01-11 | 2023-01-11 |