2022년 상반기 북한 공격 그룹 공격동향 Part.2 : 비문서형 기반 악성코드

2022-10-07 Igloo North Korean attack group attack trends in the first half of 2022 Part.2: Non-document-based malware

https://www.igloo.co.kr/security-information/2022%EB%85%84-%EC%83%81%EB%B0%98%EA%B8%B0-%EB%B6%81%ED%95%9C-%EA%B3%B5%EA%B2%A9-%EA%B7%B8%EB%A3%B9-%EA%B3%B5%EA%B2%A9%EB%8F%99%ED%96%A5-part-2-%EB%B9%84%EB%AC%B8%EC%84%9C%ED%98%95-%EA%B8%B0%EB%B0%98/

Thumbnail for 2022년 상반기 북한 공격 그룹 공격동향 Part.2 : 비문서형 기반 악성코드

IGLOO analyzed non-document-based malware used by North Korean attack groups in the first half of 2022, focusing on NukeSped and attacks abusing INITECH processes. The excerpt describes NukeSped as a Lazarus backdoor installed against domestic companies, distributed through malicious macros and targeted watering-hole activity, with RC4-encrypted data, in-memory execution, command reception from C2, keylogging, clipboard capture, privilege checks, and batch-file self-deletion. A second case describes Lazarus activity against defense, chemical, and other organizations using spear-phishing to download HTM files that were injected into the legitimate INISAFE Web EX Client process for privilege acquisition and information theft. The INITECH-abuse sample dynamically loaded networking and registry APIs, attempted credential dumping and persistence through BAT files and scheduled tasks, and used registry changes with fodhelper.exe and ComputerDefaults.exe for UAC bypass.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://www.academia.edu/427552… 2022-10-07 2022-10-07
HASH b213063f28e308adadf63d3b506e794e 2022-04-18 2022-10-07

Related Reports

« Back