隐藏在投资推介书中的淘金者-APT-C-26(Lazarus)攻击活动分析报告

2022-04-19 Qihoo360 Gold Diggers Hidden in Investment Promotional Books-APT-C-26 (Lazarus) Attack Activity Analysis Report

https://mp.weixin.qq.com/s/Xs54_RDKU5MvkvsPPCGKEw

Thumbnail for 隐藏在投资推介书中的淘金者-APT-C-26(Lazarus)攻击活动分析报告

360 attributed multiple 2021 attacks to APT-C-26/Lazarus, assessing the activity as aligned with the BlueNoroff branch and focused on cryptocurrency theft. The lure was a Venture Labo Investment Pitch Deck document using remote template injection through CVE-2017-0199, prompting users to enable macros before retrieving attacker-controlled content. The macro read encrypted data from customXml/item1.xml, decoded it, and injected shellcode into explorer.exe on 64-bit systems or notepad.exe on 32-bit systems. The payload contacted cloud.beenos.biz infrastructure, collected host, user, timezone, operating system, hardware, proxy, and process information, encrypted it with AES, and posted it to the C2 while masquerading traffic as image content. The report notes overlap with prior BlueNoroff tradecraft and IOCs, including venturelabo.co and azureword.com infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0b409e7435f4c453ffe1f5160004dbc9 2022-04-19 2022-04-19
HASH 6dca2cf173773fe8fb9d7ba5d912b95c 2022-04-19 2022-04-19
HASH 44ad56e3ee5cebb77830c0133e671f4e 2022-04-19 2022-04-19
HASH 67dc0b3d3df594094c7d5ddd2382c6c6 2022-04-19 2022-04-19
HASH 98f765bb4201ec61a304f49a97e4f305 2022-04-19 2022-04-19
HASH 648c9479b357cfdbdfcce497b4e6bff5 2022-04-19 2022-04-19
URL https://cloud.beenos.biz/MJuuKO… 2022-04-19 2022-04-19
URL https://cloud.beenos.biz/NZLCuY… 2022-04-19 2022-04-19
URL https://cloud.venturelabo.co/S9… 2022-04-19 2022-04-19
URL https://office.azureword.com/m4… 2022-04-19 2022-04-19
URL https://cloud.beenos.biz/NZLCuY… 2022-04-19 2022-04-19
URL https://cloud.beenos.biz/gM7Sy9… 2022-04-19 2022-04-19
URL https://cloud.beenos.biz/_D5l8M… 2022-04-19 2022-04-19
URL https://doc.venturelabo.co/bC%2… 2022-04-19 2022-04-19
URL https://it.zvc.capital/C5MplvLK… 2022-04-19 2022-04-19
URL https://cloud.beenos.biz/NbmU3%… 2022-04-19 2022-04-19
URL https://cloud.beenos.biz/BJD4k8… 2022-04-19 2022-04-19
URL https://cloud.beenos.biz/khhBou… 2022-04-19 2022-04-19
URL https://cloud.beenos.biz/NZLCuY… 2022-04-19 2022-04-19
DOMAIN cloud.beenos.biz 2022-04-19 2022-04-19
DOMAIN office.azureword.com 2022-04-19 2022-04-19
DOMAIN it.zvc.capital 2022-04-19 2022-04-19
HASH 89099235aad37a29b7acedc96fda0037 2022-01-13 2022-04-19
HASH f26eaa212c503aaba6e5015cb8ef44b5 2022-01-13 2022-04-19
DOMAIN doc.venturelabo.co 2022-01-13 2022-04-19
DOMAIN cloud.venturelabo.co 2022-01-13 2022-04-19

Related Actors

Related Reports

« Back