疑似Lazarus针对双平台的攻击活动披露
2019-11-04 • Qianxin • Suspected Lazarus attack activities targeting dual platforms disclosed •
https://ti.qianxin.com/blog/articles/suspected-lazarus-disclosure-of-attacks-on-dual-platforms/
QiAnXin’s threat intelligence team found Lazarus-linked attack samples for both Windows and macOS, including a Windows lure built around a psychological test that prompted users to enable macros. The Windows sample released and executed a PowerShell backdoor from the temp directory, hard-coded three C2 servers, collected host information, and supported command-driven file download and execution. A related macOS sample used a fake Flash Player component, extracted and installed a hidden .FlashUpdateCheck payload through a launchctl-loaded plist for persistence, and used backdoor functions broadly consistent with the PowerShell implant. The report attributes the activity to Lazarus based on backdoor and TTP analysis and highlights the group’s continuing ability to conduct multi-platform operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a8096ddf8758a79fdf68753190c6216a | 2019-11-04 | 2020-01-01 |
| URL | https://craypot.live/board.php | 2019-11-04 | 2019-11-20 |
| URL | https://crabbedly.club/board.php | 2019-11-04 | 2019-11-20 |
| DOMAIN | indagator.club | 2019-11-04 | 2019-11-20 |
| DOMAIN | craypot.live | 2019-11-04 | 2019-11-20 |
| DOMAIN | crabbedly.club | 2019-11-04 | 2019-11-20 |
| HASH | 6850189bbf5191a76761ab20f7c630ef | 2019-11-04 | 2019-11-12 |
| HASH | bac54e7199bd85afa5493e36d3f193d2 | 2019-11-04 | 2019-11-04 |
| URL | http://indagator.club/board.php | 2019-11-04 | 2019-11-04 |