라자루스 그룹 DLL Side-Loading 기법 이용 (mi.dll)

2022-10-06 Ahnlab Using Lazarus Group DLL Side-Loading technique (mi.dll)

https://asec.ahnlab.com/ko/39648/

Thumbnail for 라자루스 그룹 DLL Side-Loading 기법 이용 (mi.dll)

AhnLab observed Lazarus using DLL side-loading during early intrusion activity to run malicious code through legitimate Microsoft binaries, including wsmprovhost.exe and dfrgui.exe. The intrusion chain involved an older INITECH process distributing the scskapplink.dll backdoor, followed by suspected execution of additional payloads from wsmprovhost.exe when malicious mi.dll was found in the same directories. The malicious mi.dll was based on the open-source BugTrap project, contained an AES-128 encrypted embedded binary, and decrypted and executed the next-stage malware in memory using a key passed at runtime. AhnLab linked the technique to defense evasion because malicious behavior ran inside legitimate process memory, and provided detections for SCSKAppLink.dll and mi.dll as Lazarus-related malware.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ff46decb93c6d676a37e87de57bae196 2022-10-06 2022-10-06
HASH 0cc73994988e8dce2a2eeab7bd410fad 2022-10-06 2022-10-06
HASH 54b0454163b25a38368e518e1687de5b 2022-10-06 2022-10-06
HASH 9caebeda61018e86a29c291225f0319f 2022-10-06 2022-10-06

Related Actors

Related Reports

« Back