암호화폐 거래자를 노린 Lazarus APT 공격 가속화

2019-07-02 ESTSecurity Lazarus APT attacks targeting cryptocurrency traders accelerate

https://blog.alyac.co.kr/2397

Thumbnail for 암호화폐 거래자를 노린 Lazarus APT 공격 가속화

ESRC reports a run of APT activity against South Korea involving Lazarus, Kimsuky, and Geumseong121, with the highlighted Lazarus case targeting cryptocurrency-related individuals through a malicious HWP document disguised as a student project report. The attachment used an embedded malicious PostScript stream and XOR-decoded shellcode to attempt downloads from command-and-control URLs hosted under compromised WordPress paths. A later HWP variant, disguised as an air-conditioner maintenance document, reused the same structure and execution flow while switching to calderonflooring[.]com-hosted payload URLs. The activity matters because the same South Korea-focused threat landscape combined espionage-oriented targeting with financially motivated attacks against cryptocurrency users and exchanges.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN darvishkhan.net 2019-07-02 2021-04-14
URL https://darvishkhan.net/wp-cont… 2019-07-02 2020-07-06
HASH 35c6cf8858c2516b151dce81b7473bff 2019-07-02 2019-07-02
HASH bb157732cb52b6d30c624dfb111d0264 2019-07-02 2019-07-02
HASH 106f24660aa878c6aaa5f30422d1916b 2019-07-02 2019-07-02
URL https://www.calderonflooring.co… 2019-07-02 2019-07-02
URL https://darvishkhan.net/wp-cont… 2019-07-02 2019-07-02
URL https://www.calderonflooring.co… 2019-07-02 2019-07-02

Related Actors

Related Reports

« Back