破壳行动 - Lazarus(APT-C-26)组织针对安全研究人员的定向攻击活动揭秘
2021-01-26 • Qihoo360 • Operation Breaking the Shell – Revealing the Lazarus (APT-C-26) group's targeted attacks against security researchers •
360 attributed “Operation Breaking the Shell” to Lazarus/APT-C-26 and described it as a long-prepared campaign against security researchers. The operators built credibility by registering social-media personas, running the blog blog.br0vvnn[.]io, publishing vulnerability-analysis posts, and sharing the content through Twitter, GitHub, YouTube, and security-media amplification. They then sent malicious exploit PoC source packages whose Visual Studio project files executed hidden DLL payloads through PowerShell during the build process. 360 linked the activity to Lazarus through sample similarities with prior Dream Job malware and shared infrastructure, warning that compromise of researchers could expose security companies and vulnerability research.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 35545d891ea9370dfef9a8a2ab1cf95d | 2021-01-26 | 2021-01-28 |
| DOMAIN | blog.br0vvnn.io | 2021-01-25 | 2021-01-28 |