라자루스 그룹의 BYOVD를 활용한 루트킷 악성코드 분석 보고서
2022-09-22 • Ahnlab • Rootkit malware analysis report using Lazarus Group's BYOVD •
Attachments
AhnLab's report analyzes Lazarus rootkit malware that uses a bring-your-own-vulnerable-driver technique to obtain kernel-level capabilities. The PDF frames the case as part of Lazarus activity tracked by ASEC against South Korean defense, satellite, software, media, and other organizations since 2021. The report focuses on the malware's driver-abuse approach, rootkit behavior, and forensic artifacts, showing how Lazarus can use vulnerable legitimate components to interfere with detection and maintain deeper control over compromised Windows systems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 98e58a39ede26af7980ed4de2873caab | 2022-09-22 | 2022-10-24 |
| HASH | 013b4c4e9387d8fe1eab738c42c451da | 2022-09-22 | 2022-10-24 |
| DOMAIN | public.cnotools.studio | 2022-09-22 | 2022-09-30 |
| HASH | c40643751b426dec01bd390e192b4542 | 2022-09-22 | 2022-09-22 |
| HASH | a6e309f97ffada2d4d0d4aecfb255a91 | 2022-09-22 | 2022-09-22 |
| URL | https://public.cnotools.studio/… | 2022-09-22 | 2022-09-22 |
| URL | https://www.amazon.com/Windows-… | 2022-09-22 | 2022-09-22 |
| URL | https://public.cnotools.studio/… | 2022-09-22 | 2022-09-22 |
Related Actors
Related Reports
Shares tags: BYOVD, Lazarus • Shares 2 IOCs • Same author: Ahnlab
2023-02-27 •
75% Match
#BYOVD
#Lazardoor
#Lazarus
#T1059.003
#T1070.004
#T1587.001
#T1071.001
#T1046
#T1102
#T1562.001
#T1203
#T1588.002
#T1070.006
#T1068
#T1070
#T1210
#T1587.004
Shares tags: BYOVD, Lazarus • Same author: Ahnlab
Shares tag: Lazarus • Same author: Ahnlab • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Same author: Ahnlab