북한 Lazarus 그룹의 IPMsg 설치 파일 위장 악성코드 분석

2025-05-16 Igloo Cyber threat report on Lazarus, IPMsg

https://www.igloopedia.com/1caf216a-760c-807e-8aef-daa4cb009201

Thumbnail for 북한 Lazarus 그룹의 IPMsg 설치 파일 위장 악성코드 분석

The report analyzes Lazarus malware disguised as an IP Messenger installer using the filename of a legitimate IPMsg setup package. The malicious installer decrypts and filelessly loads embedded DLL components, then runs a legitimate installer from the user's AppData directory to hide the infection from the user. The DLL chain includes anti-reversing checks, such as requiring a specific parameter before execution, and can communicate persistently with up to three C2 servers. The malware can download ZIP-packaged malicious DLLs from C2 and execute them for follow-on activity, while attempting to evade sandbox and automated analysis.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d4e2bd08c8366be665e54592dec1a7ce 2025-05-16 2025-05-16
HASH a31f8f6e6078f9f59d195e3e2f29d1b3 2025-05-16 2025-05-16
HASH 8459e1c6f6c1d3996b3a86146eb961bf 2025-05-16 2025-05-16
HASH a7b23cd8b09a3ce918a77de355e9d3e5 2024-12-26 2025-05-16
URL https://cryptocopedia.com/upgra… 2024-12-26 2025-05-16
DOMAIN cryptocopedia.com 2024-07-08 2025-05-16

Related Actors

Related Reports

« Back