疑似Lazarus(APT-Q-1)涉及npm包供应链的攻击样本分析

2023-12-08 Qianxin Analysis of attack samples suspected of Lazarus (APT-Q-1) involving npm package supply chain

https://mp.weixin.qq.com/s/f5YE12w3x3wad5EO0EB53Q

Thumbnail for 疑似Lazarus(APT-Q-1)涉及npm包供应链的攻击样本分析

QiAnXin analyzes downloader samples tied to an npm package supply-chain poisoning incident that it assesses as likely Lazarus based on code overlap with historical Lazarus samples and the group's prior use of supply-chain attacks. The loader decrypts embedded PE and ZIP data, drops IconCache.db and NTUSER.DAT under the user's Roaming Microsoft paths, and establishes persistence through scheduled tasks, HKCU Run, or the Startup folder. The main downloader contacts C2 to request payload metadata, downloads numbered payloads, verifies MD5 hashes, decrypts PE content in memory, and executes specified export functions through rundll32-style loading. The report links the activity to infrastructure including 91.206.178.125, blockchain-newtech.com, chaingrown.com, and 156.236.76.9, while comparing the loading method and constants with earlier Lazarus-linked Comebacker and 3CX-related research.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 91.206.178.125 2023-11-04 2024-07-05
DOMAIN blockchain-newtech.com 2023-12-08 2024-05-28
DOMAIN chaingrown.com 2023-12-08 2024-05-28
URL https://blockchain-newtech.com/… 2023-12-08 2024-02-28
URL https://chaingrown.com/manage/m… 2023-12-08 2024-02-28
HASH 420a13202d271babc32bf8259cdaddf3 2023-12-08 2024-02-28
IPv4 103.179.142.171 2023-11-04 2024-01-19
HASH 1c4227bf06121fe9c454a85ad9245b56 2023-12-08 2023-12-08
HASH d8a8cc25bf5ef5b96ff7a64f663cbd29 2023-12-08 2023-12-08
HASH a6e7c231a699d4efe85080ce5fb36dfb 2023-12-08 2023-12-08
HASH 46127a35b73b714a9c5c58aaa43cb51f 2023-12-08 2023-12-08
HASH 7298b1f10ee6afab5e8bf648be1ca13b 2023-12-08 2023-12-08
IPv4 156.236.76.9 2023-12-08 2023-12-08

Related Actors

Related Reports

« Back