윈도우 서버를 공격해 악성코드 배포 서버로 사용하는 Lazarus 공격 그룹
2023-07-14 • Ahnlab • The Lazarus attack group attacks Windows servers and uses them as malware distribution servers. •
AhnLab reported that Lazarus compromised Windows IIS web servers and repurposed them as malware distribution servers for attacks exploiting unpatched INISAFE CrossWeb EX installations. In the observed server compromise, IIS worker process w3wp.exe created Lazarus tooling, including a Themida-packed JuicyPotato privilege-escalation binary named usopriv.exe and a DLL loader named usoshared.dat executed via rundll32. The loader searched several paths for a GIF-masquerading encoded data file, decrypted configuration and PE data, and was consistent with Lazarus loaders that run downloader or backdoor payloads in memory. AhnLab tied the infrastructure to ongoing attempts to deliver SCSKAppLink.dll through INISAFE exploitation and urged patching exposed IIS and INITECH-related assets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 280152dfeb6d3123789138c0a396f30d | 2023-07-14 | 2023-07-24 |
| HASH | d0572a2dd4da042f1c64b542e24549d9 | 2023-07-14 | 2023-07-24 |