A cascade of compromise: unveiling Lazarus' new campaign

2023-10-27 Kaspersky

https://securelist.com/unveiling-lazarus-new-campaign/110888/

Lazarus compromised a software vendor through unpatched legitimate software and continued exploiting that vendor’s software while targeting other software makers, suggesting interest in source code theft or supply-chain tampering. The campaign deployed SIGNBT for victim control and also used LPEClient, a Lazarus tool associated in the excerpt with victim profiling and payload delivery in attacks on defense contractors and the cryptocurrency industry. Post-exploitation activity appeared inside legitimate security software processes, with SIGNBT loaded in memory by shellcode and supported by persistence methods including ualapi.dll side-loading through spoolsv.exe and registry-based execution of legitimate files. The loader verifies a specific MachineGuid before decrypting a payload from a hard-coded local path, and SIGNBT then reads encrypted configuration containing C2 proxy addresses, sleep intervals, version data, monitored targets, and other operational parameters. Its C2 protocol uses SIGNBT-prefixed stages, victim profiling through the CCBrush class, randomized HTTP parameters, AES-encrypted tasking, and backdoor functions invoked when the server returns commands rather than a keep-alive response.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 54df2984e833ba2854de670cce43b823 2023-10-27 2023-10-27
HASH 9b62352851c9f82157d1d7fcafeb49d3 2023-10-27 2023-10-27
HASH e6fa116ef2705ecf9677021e5e2f691e 2023-10-27 2023-10-27
HASH 88a96f8730b35c7406d57f23bbba734d 2023-10-27 2023-10-27
HASH e89fa6345d06da32f9c8786b65111928 2023-10-27 2023-10-27
HASH 3a77b5054c36e6812f07366fb70b007d 2023-10-27 2023-10-27
HASH 31af3e7fff79bc48a99b8679ea74b589 2023-10-27 2023-10-27
HASH ae00b0f490b122ebab614d98bb2361f7 2023-10-27 2023-10-27
HASH 9cd90dff2d9d56654dbecdcd409e1ef3 2023-10-27 2023-10-27
URL https://hicar.kalo.kr/data/rent… 2023-10-27 2023-10-27
URL https://hspje.com:80/menu6/teac… 2023-10-27 2023-10-27
URL http://ictm.or.kr/UPLOAD_file/b… 2023-10-27 2023-10-27
URL https://mainbiz.or.kr/SmartEdit… 2023-10-27 2023-10-27
URL https://www.happinesscc.com/mob… 2023-10-27 2023-10-27
URL https://pms.nninc.co.kr/app/con… 2023-10-27 2023-10-27
URL https://vnfmal2022.com/niabbs5/… 2023-10-27 2023-10-27
URL http://www.vietjetairkorea.com/… 2023-10-27 2023-10-27
URL https://www.seoulanesthesia.or.… 2023-10-27 2023-10-27
URL https://little-pet.com/web/boar… 2023-10-27 2023-10-27
URL https://kstr.radiology.or.kr/up… 2023-10-27 2023-10-27
URL https://www.medric.or.kr/Contro… 2023-10-27 2023-10-27
URL https://new-q-cells.com/upload/… 2023-10-27 2023-10-27
URL https://warevalley.com/en/commo… 2023-10-27 2023-10-27
URL http://www.khmcpharm.com/Lib/Mo… 2023-10-27 2023-10-27
URL https://swt-keystonevalve.com/d… 2023-10-27 2023-10-27
URL https://api.shw.kr/login_admin/… 2023-10-27 2023-10-27
URL http://theorigin.co.kr:443/admi… 2023-10-27 2023-10-27
URL https://www.muijae.com/daumedit… 2023-10-27 2023-10-27
URL https://www.blastedlevels.com/l… 2023-10-27 2023-10-27
URL https://www.friendmc.com:80/upl… 2023-10-27 2023-10-27
URL https://www.muijae.com/daumedit… 2023-10-27 2023-10-27
URL https://pediatrics.or.kr/PubRea… 2023-10-27 2023-10-27
URL https://www.siriuskorea.co.kr/m… 2023-10-27 2023-10-27
URL http://ucware.net/skins/PHPMail… 2023-10-27 2023-10-27
URL https://admin.esangedu.kr/XPayS… 2023-10-27 2023-10-27
URL http://samwoosystem.co.kr/board… 2023-10-27 2023-10-27
URL https://www.healthpro.or.kr/upl… 2023-10-27 2023-10-27
URL http://www.hankooktop.com/ko/co… 2023-10-27 2023-10-27
URL https://www.seouldementia.or.kr… 2023-10-27 2023-10-27
URL https://www.nonstopexpress.com/… 2023-10-27 2023-10-27
URL https://www.droof.kr/Board/html… 2023-10-27 2023-10-27
URL https://kscmfs.or.kr/member/han… 2023-10-27 2023-10-27
URL http://www.friendmc.com/upload/… 2023-10-27 2023-10-27
URL https://mainbiz.or.kr/include/c… 2023-10-27 2023-10-27
URL https://safemotors.co.kr/daumed… 2023-10-27 2023-10-27
URL https://www.hanlasangjo.com/edi… 2023-10-27 2023-10-27
URL http://yoohannet.kr/min/tmp/pro… 2023-10-27 2023-10-27
URL https://yoohannet.kr/min/tmp/pr… 2023-10-27 2023-10-27
DOMAIN theorigin.co.kr 2023-10-27 2023-10-27
DOMAIN warevalley.com 2023-10-27 2023-10-27
DOMAIN pediatrics.or.kr 2023-10-27 2023-10-27
DOMAIN safemotors.co.kr 2023-10-27 2023-10-27
DOMAIN samwoosystem.co.kr 2023-10-27 2023-10-27
DOMAIN admin.esangedu.kr 2023-10-27 2023-10-27
DOMAIN api.shw.kr 2023-10-27 2023-10-27
DOMAIN hicar.kalo.kr 2023-10-27 2023-10-27
DOMAIN hspje.com 2023-10-27 2023-10-27
DOMAIN kstr.radiology.or.kr 2023-10-27 2023-10-27
DOMAIN ictm.or.kr 2023-10-27 2023-10-27
DOMAIN new-q-cells.com 2023-10-27 2023-10-27
DOMAIN vnfmal2022.com 2023-10-27 2023-10-27
DOMAIN little-pet.com 2023-10-27 2023-10-27
DOMAIN pms.nninc.co.kr 2023-10-27 2023-10-27
DOMAIN ucware.net 2023-10-27 2023-10-27
DOMAIN swt-keystonevalve.com 2023-06-08 2023-10-27

Related Reports

2023-09-27 • 34% Match
#CVE-2021-40444 #MataDoor #DarkRiver #T1082 #T1059.003 #T1140 #T1005 #T1041 #T1046 #T1112 #T1083 #T1071 #T1124 #T1057 #T1566.001 #T1620 #T1129 #T1622 #T1135 #T1027.002 #T1090.003 #T1008 #T1571 #T1049 #T1016 #T1018 #T1074.001 #T1218.011 #T1036.004 #T1218.010 #T1106 #T1090.001 #T1095 #T1033 #T1543.003 #T1090.002 #T1560.002 #T1132 #T1030 #T1572 #T1572.001 #T1572.002
Shares tags: T1082, T1140, T1041 • Published within a month
2025-04-24 • 33% Match
#ThreatNeedle #LPEClient #SIGNBT #AGAMEMNON #Lazarus #Innorix #SyncHole #CrossEX #T1027.013 #T1082 #T1140 #T1071.001 #T1083 #T1057 #T1583.003 #T1583.001 #T1105 #T1620 #T1574.002 #T1135 #T1573.001 #T1190 #T1189 #T1049 #T1573.002 #T1016 #T1087.001 #T1218.011 #T1584.001 #T1574.001 #T1564.004 #T1027.009 #T1569.002 #T1543.003 #T1087.002 #T1570 #T1608.004 #T1547.005 #T1007
Shares tags: LPEClient, SIGNBT, T1082 • Same author: Kaspersky
2021-12-02 • 25% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1573.001 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004 #T0865
Shares tags: T1082, T1140, T1041
2025-08-13 • 23% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1218.010 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1573 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004
Shares tags: T1082, T1140, T1041
« Back