라자루스(Lazarus) APT 조직, 텔레그램 메신저로 '진실겜.xls' 악성 파일 공격
2019-06-27 • ESTSecurity • Lazarus APT organization attacks ‘TruthGame.xls' malicious file through Telegram messenger •
ESRC attributed a Telegram-delivered malicious Excel workbook to Lazarus APT activity after finding it under a victim’s Telegram Desktop download path. The file used an Auto_Open macro built from old sample code to create and run a PowerShell script intended for bot-style command-and-control activity. ESRC observed that the PowerShell component shared C2 communication traits and code with earlier Lazarus tooling and was live at analysis time, collecting victim information and monitoring additional payloads. The report assessed the targeting and tool overlap as consistent with a focused attack rather than broad indiscriminate distribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 64edec1d585ba599354f927249e12e6d | 2019-06-27 | 2019-06-27 |
| URL | https://pegasusco.net | 2019-06-27 | 2019-06-27 |
| URL | https://smilekeepers.co | 2019-06-27 | 2019-06-27 |
| URL | https://czinfo.club | 2019-06-27 | 2019-06-27 |
| DOMAIN | smilekeepers.co | 2019-06-27 | 2019-06-27 |
| DOMAIN | pegasusco.net | 2019-06-27 | 2019-06-27 |
| DOMAIN | czinfo.club | 2019-06-27 | 2019-06-27 |