윈도우 서버를 공격해 악성코드 배포 서버로 사용하는 Lazarus 공격 그룹

2023-07-14 Ahnlab The Lazarus attack group attacks Windows servers and uses them as malware distribution servers.

https://asec.ahnlab.com/ko/55252/

Thumbnail for 윈도우 서버를 공격해 악성코드 배포 서버로 사용하는 Lazarus 공격 그룹

AhnLab reported that Lazarus compromised Windows IIS web servers and repurposed them as malware distribution servers for attacks exploiting unpatched INISAFE CrossWeb EX installations. In the observed server compromise, IIS worker process w3wp.exe created Lazarus tooling, including a Themida-packed JuicyPotato privilege-escalation binary named usopriv.exe and a DLL loader named usoshared.dat executed via rundll32. The loader searched several paths for a GIF-masquerading encoded data file, decrypted configuration and PE data, and was consistent with Lazarus loaders that run downloader or backdoor payloads in memory. AhnLab tied the infrastructure to ongoing attempts to deliver SCSKAppLink.dll through INISAFE exploitation and urged patching exposed IIS and INITECH-related assets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 280152dfeb6d3123789138c0a396f30d 2023-07-14 2023-07-24
HASH d0572a2dd4da042f1c64b542e24549d9 2023-07-14 2023-07-24

Related Reports

« Back