라자루스(Lazarus) APT NetSupport RAT 분석 보고서 1편

2025-02-03 Nurilab Lazarus APT NetSupport RAT Analysis Report, Part 1

https://blog.naver.com/nurilab1/223746489719

Thumbnail for 라자루스(Lazarus) APT NetSupport RAT 분석 보고서 1편

NuriLab reports a Lazarus-attributed NetSupport RAT campaign that used fake CAPTCHA instructions to push victims into running a PowerShell command. The chain created C:/Users/Public/as, downloaded a ZIP from 147.45.xx.200, extracted NetSupport Manager components, and launched client32.exe with a client32.ini configured to connect to attacker C2. The lure reportedly impersonated Raiffeisen Bank International and targeted Ukrainians, combining social engineering with signed remote-access tooling to reduce suspicion.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5d5e67fb50030d44113ab3fff345319… 2025-02-03 2025-02-03
IPv4 147.45.44.200 2025-02-03 2025-02-03
IPv4 147.45.44.201 2025-02-03 2025-02-03

Related Actors

Related Reports

« Back