국내 금융 보안 솔루션의 취약점을 이용하는 Lazarus 공격 그룹

2023-06-08 Ahnlab Lazarus attack group exploits vulnerabilities in domestic financial security solutions

https://asec.ahnlab.com/ko/53832/

Thumbnail for 국내 금융 보안 솔루션의 취약점을 이용하는 Lazarus 공격 그룹

AhnLab reports that Lazarus exploited vulnerabilities in South Korean financial and enterprise security software, expanding beyond previously abused INISAFE CrossWeb EX and MagicLine4NX to VestCert and TCO!Stream zero-days. The group used watering-hole access against systems with vulnerable VestCert installations to launch PowerShell, contact C2 servers, and download malware such as WinSync.dll. For internal propagation, attacker-built tooling abused TCO!Stream client behavior on TCP 3511 to instruct endpoints to download and execute staged files from the management server. AhnLab notes KISA/vendor coordination and urges manual removal or reinstallation because affected products were not automatically updated.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN swt-keystonevalve.com 2023-06-08 2023-10-27
HASH ec5d5941522d947abd6c9e82e615b46… 2023-06-08 2023-06-14
HASH 8adeeb291b48c97db1816777432d97fd 2023-06-08 2023-06-14
HASH 55f0225d58585d60d486a3cc7eb93de5 2023-06-08 2023-06-14
HASH 3ca6abf845f3528edf58418e5e42a9c… 2023-06-08 2023-06-14
URL http://ksmarathon.com/admin/exc… 2023-06-08 2023-06-14
URL https://www.bcdm.or.kr/board/ty… 2023-06-08 2023-06-14
URL https://swt-keystonevalve.com/d… 2023-06-08 2023-06-14
URL https://www.hmedical.co.kr/incl… 2023-06-08 2023-06-14
URL https://www.gongsilbox.com/boar… 2023-06-08 2023-06-14
URL https://www.coupontreezero.com/… 2023-06-08 2023-06-14
URL http://www.sinae.or.kr/sub01/in… 2023-06-08 2023-06-14
URL https://www.daehang.com/member/… 2023-06-08 2023-06-14
URL https://www.materic.or.kr/files… 2023-06-08 2023-06-14
HASH e7c9bf8bf075487a2d91e0561b86d6f5 2023-03-17 2023-06-14
HASH e73eab80b75887d4e8dd6df33718e3a5 2023-02-15 2023-06-14
HASH 747177aad5aef020b82c6aeabe5b174f 2023-02-15 2023-06-14
HASH 064d696a93a3790bd3a1b8b76baaeef3 2023-02-15 2023-06-14
HASH c09b062841e2c4d46c2e5270182d4272 2023-02-15 2023-06-14
HASH 67d306c163b38a06e98da5711e14c5a7 2023-02-15 2023-06-14
HASH ba741fa4c7b4bb97165644c799e29c99 2023-02-15 2023-06-14

Related Reports

« Back