라자루스(Lazarus) 그룹, 한국 증권사 직원을 노린 APT 공격 시도

2020-05-27 ESTSecurity Lazarus group attempts APT attack targeting Korean securities company employees

https://blog.alyac.co.kr/3018

Thumbnail for 라자루스(Lazarus) 그룹, 한국 증권사 직원을 노린 APT 공격 시도

ESRC analyzed a spear-phishing attack against a South Korean securities-company employee and attributed the operation to Lazarus. The email carried many HWP, XLSX, JPEG, and large attachments as decoys, with the first HWP file containing malicious PostScript data that launched shellcode. The shellcode created %appdata%\Microsoft\Internet Explorer\security.vbs, contacted sixbitsmedia[.]com to download an additional Base64-encoded payload disguised as a PNG, and produced a 32-bit DLL with a Crat Client-related PDB path. The follow-on malware communicated with multiple compromised WordPress-based sites, including mokawafm[.]com, tiramisu[.]it, kartacnictvi[.]cz, dimer-group[.]com, and ecolerubanvert[.]com, enabling additional attacker commands.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://mokawafm.com/wp-content… 2020-05-25 2020-05-29
DOMAIN mokawafm.com 2020-05-25 2020-05-29
URL http://www.kartacnictvi.cz/wp-c… 2020-05-27 2020-05-27
URL https://www.tiramisu.it/wp-cont… 2020-05-27 2020-05-27
URL http://www.dimer-group.com/wp-c… 2020-05-27 2020-05-27
URL https://ecolerubanvert.com/wp-c… 2020-05-27 2020-05-27
DOMAIN ecolerubanvert.com 2020-05-27 2020-05-27
URL https://sixbitsmedia.com/wp-con… 2020-05-25 2020-05-27
DOMAIN sixbitsmedia.com 2020-05-25 2020-05-27

Related Actors

Related Reports

« Back