윈도우즈 업데이트 서비스 악용, 북한 Lazarus 그룹의 신규 공격
2022-04-01 • Somansa • Abuse of Windows update service, new attack by North Korea's Lazarus group •
Attachments
Somansa analyzed a Lazarus campaign that abused Windows Update-related services and lures aimed at defense-industry hiring or remote-work security guidance. The report says North Korean hackers commonly distribute malware by impersonating organizations, institutions, or topical documents, affecting both enterprise employees and ordinary users. In this case, the malware was disguised as a normal file, infected systems after execution, and enabled theft of financial data, sensitive information, personal certificates, and connection records from compromised PCs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f14b1a91ed1ecd365088ba6de584678… | 2022-01-27 | 2022-04-01 |
| HASH | 0d01b24f7666f9bccf0f16ea97e41e0… | 2022-01-27 | 2022-04-01 |
| HASH | 829eceee720b0a3e505efbd3262c387… | 2022-01-27 | 2022-04-01 |
Related Actors
Related Reports
2022-01-27 •
100% Match
#Lazarus
Shares tag: Lazarus • Shares 3 IOCs
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month
2022-03-31 •
80% Match
#DeFi
#Lazarus
#T1082
#T1070.004
#T1041
#T1071.001
#T1083
#T1204.002
#T1124
#T1057
#T1547.001
#T1573.001
#T1070.006
Shares tag: Lazarus • Published within a week
2022-03-23 •
80% Match
#Lazarus
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus