라자루스(Lazarus) APT NetSupport RAT 분석 보고서 1편
2025-02-03 • Nurilab • Lazarus APT NetSupport RAT Analysis Report, Part 1 •
NuriLab reports a Lazarus-attributed NetSupport RAT campaign that used fake CAPTCHA instructions to push victims into running a PowerShell command. The chain created C:/Users/Public/as, downloaded a ZIP from 147.45.xx.200, extracted NetSupport Manager components, and launched client32.exe with a client32.ini configured to connect to attacker C2. The lure reportedly impersonated Raiffeisen Bank International and targeted Ukrainians, combining social engineering with signed remote-access tooling to reduce suspicion.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5d5e67fb50030d44113ab3fff345319… | 2025-02-03 | 2025-02-03 |
| IPv4 | 147.45.44.200 | 2025-02-03 | 2025-02-03 |
| IPv4 | 147.45.44.201 | 2025-02-03 | 2025-02-03 |
Related Actors
Related Reports
Shares tag: Lazarus • Same author: Nurilab • Published within a month
Shares tag: Lazarus • Same author: Nurilab • Published within a month
Shares tag: Lazarus • Same author: Nurilab • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month