라자루스(Lazarus)그룹, 미국 라스베가스 CES2020 참관단 참가신청서 사칭 APT 공격 정황 포착

2019-10-24 ESTSecurity Lazarus Group detects APT attack impersonating application form for CES 2020 observation group in Las Vegas, USA

https://blog.alyac.co.kr/2581

Thumbnail for 라자루스(Lazarus)그룹, 미국 라스베가스 CES2020 참관단 참가신청서 사칭 APT 공격 정황 포착

Alyac reported a targeted email attack that impersonated a CES 2020 delegation participation application, using a malicious HWP attachment sent to selected recipients. When opened, shellcode embedded in the Hangul document executed and was described as interfering with C2 analysis before the server delivered a 64-bit malicious DLL disguised as a video file. The excerpt identifies detections as Exploit.HWP.Agent and Trojan.Agent.113664H and gives the MD5 f865ea5f29bac6fe7f1d976a36c79713 for the malicious file. The source states the activity was related to Lazarus Group, making the HWP-based lure and staged DLL delivery relevant for tracking DPRK-linked phishing tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f865ea5f29bac6fe7f1d976a36c79713 2019-10-24 2019-11-18

Related Actors

Related Reports

« Back