라자루스(Lazarus) APT 그룹, 암호화폐 투자계약서 사칭 무비 코인 작전
2019-06-20 • ESTSecurity • Lazarus APT group conducts Movie Coin operation impersonating cryptocurrency investment contracts •
ESRC reported a Lazarus operation using a Korean cryptocurrency investment-contract HWP lure, with the malicious document dated June 2019 and built to exploit HWP processing. Embedded PostScript code used XOR encoding and shellcode to hide C2 logic, then retrieved disguised 32-bit and 64-bit DLL payloads from a compromised WordPress path as movie.png and movie.jpg. The DLLs used movie32.dll and movie64.dll export names, communicated with additional C2 endpoints, and waited for operator commands. ESRC linked the structure to earlier Lazarus Battle Cruiser and Star Cruiser activity, noting similar PostScript logic, WordPress abuse, and webshell evidence, and assessed the cryptocurrency theme as consistent with financially motivated targeting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://gozdeelektronik.net/wp-… | 2019-06-20 | 2021-10-28 |
| URL | https://gozdeelektronik.net/wp-… | 2019-06-20 | 2021-10-28 |
| DOMAIN | gozdeelektronik.net | 2019-06-20 | 2021-10-28 |
| URL | https://creativefishstudio.com/… | 2019-06-20 | 2019-06-20 |
| URL | https://rxrenew.us/wp-content/t… | 2019-06-20 | 2019-06-20 |
| URL | https://sensationalsecrets.com/… | 2019-06-20 | 2019-06-20 |
| DOMAIN | sensationalsecrets.com | 2019-06-20 | 2019-06-20 |
| DOMAIN | creativefishstudio.com | 2019-06-20 | 2019-06-20 |
| DOMAIN | rxrenew.us | 2019-06-20 | 2019-06-20 |