무기화된 오픈소스 소프트웨어

2023-06-19 Hauri Weaponized open source software

https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=51

Attachments

2023-06-07_ìì_ëì_ë³ê³ìëêíë_ìíìì_ìííìì.pdf (642 KB)

Hauri reported that Lazarus weaponized open-source tools including PuTTY, KiTTY, TightVNC, Sumatra PDF Reader, and muPDF/Subliminal Recording as part of job-themed attacks. Since June 2022, the group allegedly approached engineers on LinkedIn while impersonating recruiters from specific companies and delivered modified software such as a TightVNC-based "Amazon Workspaces.exe" inside a skill-assessment ISO. The modified tools did not execute malicious behavior immediately, instead waiting for events such as opening a specific PDF or connecting to a particular server to evade sandbox analysis.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3ef1892c1a5f1bb056871b7d7e5cd69a 2023-06-19 2023-06-19
HASH 4e10c8d3d71136e870cf58c0e31db2bc 2023-06-19 2023-06-19
URL https://www.jeannecampos.com/wp… 2023-06-19 2023-06-19

Related Reports

« Back