라자루스 그룹 DLL Side-Loading 기법 이용 (mi.dll)
2022-10-06 • Ahnlab • Using Lazarus Group DLL Side-Loading technique (mi.dll) •
AhnLab observed Lazarus using DLL side-loading during early intrusion activity to run malicious code through legitimate Microsoft binaries, including wsmprovhost.exe and dfrgui.exe. The intrusion chain involved an older INITECH process distributing the scskapplink.dll backdoor, followed by suspected execution of additional payloads from wsmprovhost.exe when malicious mi.dll was found in the same directories. The malicious mi.dll was based on the open-source BugTrap project, contained an AES-128 encrypted embedded binary, and decrypted and executed the next-stage malware in memory using a key passed at runtime. AhnLab linked the technique to defense evasion because malicious behavior ran inside legitimate process memory, and provided detections for SCSKAppLink.dll and mi.dll as Lazarus-related malware.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ff46decb93c6d676a37e87de57bae196 | 2022-10-06 | 2022-10-06 |
| HASH | 0cc73994988e8dce2a2eeab7bd410fad | 2022-10-06 | 2022-10-06 |
| HASH | 54b0454163b25a38368e518e1687de5b | 2022-10-06 | 2022-10-06 |
| HASH | 9caebeda61018e86a29c291225f0319f | 2022-10-06 | 2022-10-06 |