암호화폐 거래자를 노린 Lazarus APT 공격 가속화
2019-07-02 • ESTSecurity • Lazarus APT attacks targeting cryptocurrency traders accelerate •
ESRC reports a run of APT activity against South Korea involving Lazarus, Kimsuky, and Geumseong121, with the highlighted Lazarus case targeting cryptocurrency-related individuals through a malicious HWP document disguised as a student project report. The attachment used an embedded malicious PostScript stream and XOR-decoded shellcode to attempt downloads from command-and-control URLs hosted under compromised WordPress paths. A later HWP variant, disguised as an air-conditioner maintenance document, reused the same structure and execution flow while switching to calderonflooring[.]com-hosted payload URLs. The activity matters because the same South Korea-focused threat landscape combined espionage-oriented targeting with financially motivated attacks against cryptocurrency users and exchanges.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | darvishkhan.net | 2019-07-02 | 2021-04-14 |
| URL | https://darvishkhan.net/wp-cont… | 2019-07-02 | 2020-07-06 |
| HASH | 35c6cf8858c2516b151dce81b7473bff | 2019-07-02 | 2019-07-02 |
| HASH | bb157732cb52b6d30c624dfb111d0264 | 2019-07-02 | 2019-07-02 |
| HASH | 106f24660aa878c6aaa5f30422d1916b | 2019-07-02 | 2019-07-02 |
| URL | https://www.calderonflooring.co… | 2019-07-02 | 2019-07-02 |
| URL | https://darvishkhan.net/wp-cont… | 2019-07-02 | 2019-07-02 |
| URL | https://www.calderonflooring.co… | 2019-07-02 | 2019-07-02 |