무기화된 오픈소스 소프트웨어
2023-06-19 • Hauri • Weaponized open source software •
https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=51
Attachments
Hauri reported that Lazarus weaponized open-source tools including PuTTY, KiTTY, TightVNC, Sumatra PDF Reader, and muPDF/Subliminal Recording as part of job-themed attacks. Since June 2022, the group allegedly approached engineers on LinkedIn while impersonating recruiters from specific companies and delivered modified software such as a TightVNC-based "Amazon Workspaces.exe" inside a skill-assessment ISO. The modified tools did not execute malicious behavior immediately, instead waiting for events such as opening a specific PDF or connecting to a particular server to evade sandbox analysis.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3ef1892c1a5f1bb056871b7d7e5cd69a | 2023-06-19 | 2023-06-19 |
| HASH | 4e10c8d3d71136e870cf58c0e31db2bc | 2023-06-19 | 2023-06-19 |
| URL | https://www.jeannecampos.com/wp… | 2023-06-19 | 2023-06-19 |