疑似APT-C-26(Lazarus)组织通过加密货币钱包推广信息进行攻击活动分析

2023-01-11 Qihoo360 Suspected APT-C-26 (Lazarus) attack activity using cryptocurrency wallet promotional information

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247491718&idx=1&sn=71ac64eff7aa1dae857b12999ab03a4d&chksm=f9c1d38fceb65a9964858df003ac8fa8a17bf473be9de4b1e47543da3b203c0f0083f92d3e20&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for 疑似APT-C-26(Lazarus)组织通过加密货币钱包推广信息进行攻击活动分析

360 Advanced Threat Research Institute describes a suspected APT-C-26/Lazarus campaign delivering a malicious ISO themed around promotion of the Somora cryptocurrency wallet to cryptocurrency holders. The ISO contained wallet screenshots and a malicious “Somora Cryptocurrency Wallet” LNK that invoked PowerShell, dropped a decoy PDF, a loader DLL, and encrypted data, then executed the DLL via rundll32. The loader decrypted shellcode that restored and ran a backdoor assessed as a possible NukeSped variant based on code structure, hardcoded C2 behavior, XOR/base64 command handling, and command-execution logic similar to earlier Lazarus samples. The report lists droidnation[.]net/nation.php and long encrypted/hash artifacts as supporting indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3099980ca44cae6a68887bbcb37ac5e6 2023-01-11 2023-01-11
HASH 0ae1172aaca0ed4b63c7c5f5b1739294 2023-01-11 2023-01-11
DOMAIN droidnation.net 2023-01-11 2023-01-11

Related Actors

Related Reports

« Back