코로나19 정국에도 ‘라자루스’ 그룹 소행 국내외 APT 공격 증가 주의보

2020-04-28 ESTSecurity Warning of increased domestic and international APT attacks attributed to the ‘Lazarus' group despite the COVID-19 situation

https://blog.alyac.co.kr/2946

Thumbnail for 코로나19 정국에도 ‘라자루스’ 그룹 소행 국내외 APT 공격 증가 주의보

ESRC reported a rise in Lazarus-attributed APT activity in April 2020, including spear-phishing that impersonated a blockchain software development contract and targeted people connected to cryptocurrency trading. The same activity set also included COVID-19 infection-control lures, a malicious MS Word document about U.S.-Korea diplomacy and security, and aerospace recruitment-themed documents aimed at foreign organizations. The aerospace and diplomacy lures shared the elite4print[.]com C2 server and resembled earlier recruitment-themed Lazarus activity against an Indian aerospace and defense company. The source frames Lazarus as a state-level threat conducting both espionage and revenue-generating attacks, with detection names including Trojan.Downloader.DOC.Gen and Exploit.HWP.Agent.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN elite4print.com 2020-04-28 2022-09-29

Related Actors

Related Reports

« Back