라자루스(Lazarus) APT 조직, 텔레그램 메신저로 '진실겜.xls' 악성 파일 공격

2019-06-27 ESTSecurity Lazarus APT organization attacks ‘TruthGame.xls' malicious file through Telegram messenger

https://blog.alyac.co.kr/2388

Thumbnail for 라자루스(Lazarus) APT 조직, 텔레그램 메신저로 '진실겜.xls' 악성 파일 공격

ESRC attributed a Telegram-delivered malicious Excel workbook to Lazarus APT activity after finding it under a victim’s Telegram Desktop download path. The file used an Auto_Open macro built from old sample code to create and run a PowerShell script intended for bot-style command-and-control activity. ESRC observed that the PowerShell component shared C2 communication traits and code with earlier Lazarus tooling and was live at analysis time, collecting victim information and monitoring additional payloads. The report assessed the targeting and tool overlap as consistent with a focused attack rather than broad indiscriminate distribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 64edec1d585ba599354f927249e12e6d 2019-06-27 2019-06-27
URL https://pegasusco.net 2019-06-27 2019-06-27
URL https://smilekeepers.co 2019-06-27 2019-06-27
URL https://czinfo.club 2019-06-27 2019-06-27
DOMAIN smilekeepers.co 2019-06-27 2019-06-27
DOMAIN pegasusco.net 2019-06-27 2019-06-27
DOMAIN czinfo.club 2019-06-27 2019-06-27

Related Actors

Related Reports

« Back