疑似Lazarus针对双平台的攻击活动披露

2019-11-04 Qianxin Suspected Lazarus attack activities targeting dual platforms disclosed

https://ti.qianxin.com/blog/articles/suspected-lazarus-disclosure-of-attacks-on-dual-platforms/

Thumbnail for 疑似Lazarus针对双平台的攻击活动披露

QiAnXin’s threat intelligence team found Lazarus-linked attack samples for both Windows and macOS, including a Windows lure built around a psychological test that prompted users to enable macros. The Windows sample released and executed a PowerShell backdoor from the temp directory, hard-coded three C2 servers, collected host information, and supported command-driven file download and execution. A related macOS sample used a fake Flash Player component, extracted and installed a hidden .FlashUpdateCheck payload through a launchctl-loaded plist for persistence, and used backdoor functions broadly consistent with the PowerShell implant. The report attributes the activity to Lazarus based on backdoor and TTP analysis and highlights the group’s continuing ability to conduct multi-platform operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a8096ddf8758a79fdf68753190c6216a 2019-11-04 2020-01-01
URL https://craypot.live/board.php 2019-11-04 2019-11-20
URL https://crabbedly.club/board.php 2019-11-04 2019-11-20
DOMAIN indagator.club 2019-11-04 2019-11-20
DOMAIN craypot.live 2019-11-04 2019-11-20
DOMAIN crabbedly.club 2019-11-04 2019-11-20
HASH 6850189bbf5191a76761ab20f7c630ef 2019-11-04 2019-11-12
HASH bac54e7199bd85afa5493e36d3f193d2 2019-11-04 2019-11-04
URL http://indagator.club/board.php 2019-11-04 2019-11-04

Related Actors

Related Reports

« Back