북한 Lazarus 그룹의 IPMsg 설치 파일 위장 악성코드 분석
2025-05-16 • Igloo • Cyber threat report on Lazarus, IPMsg •
https://www.igloopedia.com/1caf216a-760c-807e-8aef-daa4cb009201
The report analyzes Lazarus malware disguised as an IP Messenger installer using the filename of a legitimate IPMsg setup package. The malicious installer decrypts and filelessly loads embedded DLL components, then runs a legitimate installer from the user's AppData directory to hide the infection from the user. The DLL chain includes anti-reversing checks, such as requiring a specific parameter before execution, and can communicate persistently with up to three C2 servers. The malware can download ZIP-packaged malicious DLLs from C2 and execute them for follow-on activity, while attempting to evade sandbox and automated analysis.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d4e2bd08c8366be665e54592dec1a7ce | 2025-05-16 | 2025-05-16 |
| HASH | a31f8f6e6078f9f59d195e3e2f29d1b3 | 2025-05-16 | 2025-05-16 |
| HASH | 8459e1c6f6c1d3996b3a86146eb961bf | 2025-05-16 | 2025-05-16 |
| HASH | a7b23cd8b09a3ce918a77de355e9d3e5 | 2024-12-26 | 2025-05-16 |
| URL | https://cryptocopedia.com/upgra… | 2024-12-26 | 2025-05-16 |
| DOMAIN | cryptocopedia.com | 2024-07-08 | 2025-05-16 |