2024년 라자루스 악성코드 특징
2025-01-24 • KRCERT • Characteristics of Lazarus Malware in 2024 •
https://krcert.or.kr/kr/bbs/view.do?bbsId=B0000127&pageIndex=1&nttId=71642&menuNo=205021
Attachments
KISA analyzes four malware types attributed to Lazarus activity observed in 2024 incidents affecting South Korean private-sector organizations, including IT companies and a major media company. The first type uses DLL side-loading, MachineGuid-based CRC32 checks, AES-128 and RC6 decryption, encrypted configuration files, and a multi-threaded remote-control component that communicates with command-and-control servers over POST requests. Another case involved hands-on attacker activity using certutil.exe to download a disguised payload and rundll32.exe to execute it, showing Living-off-the-Land tradecraft around a packed, Base64-encoded loader. KISA also details SCOUT downloader variants hidden in registry data or specific file paths, with RC4-protected configuration and window-message-based execution, and notes a separate malware type abusing NTFS Alternate Data Streams. The findings matter because they show Lazarus continuing to use modular loaders, victim-specific execution checks, stealthy storage, and remote-control tooling in domestic intrusions aimed at sensitive information theft.