2022년 상반기 북한 공격 그룹 공격동향 Part.2 : 비문서형 기반 악성코드
2022-10-07 • Igloo • North Korean attack group attack trends in the first half of 2022 Part.2: Non-document-based malware •
IGLOO analyzed non-document-based malware used by North Korean attack groups in the first half of 2022, focusing on NukeSped and attacks abusing INITECH processes. The excerpt describes NukeSped as a Lazarus backdoor installed against domestic companies, distributed through malicious macros and targeted watering-hole activity, with RC4-encrypted data, in-memory execution, command reception from C2, keylogging, clipboard capture, privilege checks, and batch-file self-deletion. A second case describes Lazarus activity against defense, chemical, and other organizations using spear-phishing to download HTM files that were injected into the legitimate INISAFE Web EX Client process for privilege acquisition and information theft. The INITECH-abuse sample dynamically loaded networking and registry APIs, attempted credential dumping and persistence through BAT files and scheduled tasks, and used registry changes with fodhelper.exe and ComputerDefaults.exe for UAC bypass.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.academia.edu/427552… | 2022-10-07 | 2022-10-07 |
| HASH | b213063f28e308adadf63d3b506e794e | 2022-04-18 | 2022-10-07 |