라자루스(Lazarus) APT 그룹, 암호화폐 투자계약서 사칭 무비 코인 작전

2019-06-20 ESTSecurity Lazarus APT group conducts Movie Coin operation impersonating cryptocurrency investment contracts

https://blog.alyac.co.kr/2377

Thumbnail for 라자루스(Lazarus) APT 그룹, 암호화폐 투자계약서 사칭 무비 코인 작전

ESRC reported a Lazarus operation using a Korean cryptocurrency investment-contract HWP lure, with the malicious document dated June 2019 and built to exploit HWP processing. Embedded PostScript code used XOR encoding and shellcode to hide C2 logic, then retrieved disguised 32-bit and 64-bit DLL payloads from a compromised WordPress path as movie.png and movie.jpg. The DLLs used movie32.dll and movie64.dll export names, communicated with additional C2 endpoints, and waited for operator commands. ESRC linked the structure to earlier Lazarus Battle Cruiser and Star Cruiser activity, noting similar PostScript logic, WordPress abuse, and webshell evidence, and assessed the cryptocurrency theme as consistent with financially motivated targeting.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://gozdeelektronik.net/wp-… 2019-06-20 2021-10-28
URL https://gozdeelektronik.net/wp-… 2019-06-20 2021-10-28
DOMAIN gozdeelektronik.net 2019-06-20 2021-10-28
URL https://creativefishstudio.com/… 2019-06-20 2019-06-20
URL https://rxrenew.us/wp-content/t… 2019-06-20 2019-06-20
URL https://sensationalsecrets.com/… 2019-06-20 2019-06-20
DOMAIN sensationalsecrets.com 2019-06-20 2019-06-20
DOMAIN creativefishstudio.com 2019-06-20 2019-06-20
DOMAIN rxrenew.us 2019-06-20 2019-06-20

Related Actors

Related Reports

« Back