A cascade of compromise: unveiling Lazarus' new campaign
2023-10-27 • Kaspersky •
https://securelist.com/unveiling-lazarus-new-campaign/110888/
Lazarus compromised a software vendor through unpatched legitimate software and continued exploiting that vendor’s software while targeting other software makers, suggesting interest in source code theft or supply-chain tampering. The campaign deployed SIGNBT for victim control and also used LPEClient, a Lazarus tool associated in the excerpt with victim profiling and payload delivery in attacks on defense contractors and the cryptocurrency industry. Post-exploitation activity appeared inside legitimate security software processes, with SIGNBT loaded in memory by shellcode and supported by persistence methods including ualapi.dll side-loading through spoolsv.exe and registry-based execution of legitimate files. The loader verifies a specific MachineGuid before decrypting a payload from a hard-coded local path, and SIGNBT then reads encrypted configuration containing C2 proxy addresses, sleep intervals, version data, monitored targets, and other operational parameters. Its C2 protocol uses SIGNBT-prefixed stages, victim profiling through the CCBrush class, randomized HTTP parameters, AES-encrypted tasking, and backdoor functions invoked when the server returns commands rather than a keep-alive response.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 54df2984e833ba2854de670cce43b823 | 2023-10-27 | 2023-10-27 |
| HASH | 9b62352851c9f82157d1d7fcafeb49d3 | 2023-10-27 | 2023-10-27 |
| HASH | e6fa116ef2705ecf9677021e5e2f691e | 2023-10-27 | 2023-10-27 |
| HASH | 88a96f8730b35c7406d57f23bbba734d | 2023-10-27 | 2023-10-27 |
| HASH | e89fa6345d06da32f9c8786b65111928 | 2023-10-27 | 2023-10-27 |
| HASH | 3a77b5054c36e6812f07366fb70b007d | 2023-10-27 | 2023-10-27 |
| HASH | 31af3e7fff79bc48a99b8679ea74b589 | 2023-10-27 | 2023-10-27 |
| HASH | ae00b0f490b122ebab614d98bb2361f7 | 2023-10-27 | 2023-10-27 |
| HASH | 9cd90dff2d9d56654dbecdcd409e1ef3 | 2023-10-27 | 2023-10-27 |
| URL | https://hicar.kalo.kr/data/rent… | 2023-10-27 | 2023-10-27 |
| URL | https://hspje.com:80/menu6/teac… | 2023-10-27 | 2023-10-27 |
| URL | http://ictm.or.kr/UPLOAD_file/b… | 2023-10-27 | 2023-10-27 |
| URL | https://mainbiz.or.kr/SmartEdit… | 2023-10-27 | 2023-10-27 |
| URL | https://www.happinesscc.com/mob… | 2023-10-27 | 2023-10-27 |
| URL | https://pms.nninc.co.kr/app/con… | 2023-10-27 | 2023-10-27 |
| URL | https://vnfmal2022.com/niabbs5/… | 2023-10-27 | 2023-10-27 |
| URL | http://www.vietjetairkorea.com/… | 2023-10-27 | 2023-10-27 |
| URL | https://www.seoulanesthesia.or.… | 2023-10-27 | 2023-10-27 |
| URL | https://little-pet.com/web/boar… | 2023-10-27 | 2023-10-27 |
| URL | https://kstr.radiology.or.kr/up… | 2023-10-27 | 2023-10-27 |
| URL | https://www.medric.or.kr/Contro… | 2023-10-27 | 2023-10-27 |
| URL | https://new-q-cells.com/upload/… | 2023-10-27 | 2023-10-27 |
| URL | https://warevalley.com/en/commo… | 2023-10-27 | 2023-10-27 |
| URL | http://www.khmcpharm.com/Lib/Mo… | 2023-10-27 | 2023-10-27 |
| URL | https://swt-keystonevalve.com/d… | 2023-10-27 | 2023-10-27 |
| URL | https://api.shw.kr/login_admin/… | 2023-10-27 | 2023-10-27 |
| URL | http://theorigin.co.kr:443/admi… | 2023-10-27 | 2023-10-27 |
| URL | https://www.muijae.com/daumedit… | 2023-10-27 | 2023-10-27 |
| URL | https://www.blastedlevels.com/l… | 2023-10-27 | 2023-10-27 |
| URL | https://www.friendmc.com:80/upl… | 2023-10-27 | 2023-10-27 |
| URL | https://www.muijae.com/daumedit… | 2023-10-27 | 2023-10-27 |
| URL | https://pediatrics.or.kr/PubRea… | 2023-10-27 | 2023-10-27 |
| URL | https://www.siriuskorea.co.kr/m… | 2023-10-27 | 2023-10-27 |
| URL | http://ucware.net/skins/PHPMail… | 2023-10-27 | 2023-10-27 |
| URL | https://admin.esangedu.kr/XPayS… | 2023-10-27 | 2023-10-27 |
| URL | http://samwoosystem.co.kr/board… | 2023-10-27 | 2023-10-27 |
| URL | https://www.healthpro.or.kr/upl… | 2023-10-27 | 2023-10-27 |
| URL | http://www.hankooktop.com/ko/co… | 2023-10-27 | 2023-10-27 |
| URL | https://www.seouldementia.or.kr… | 2023-10-27 | 2023-10-27 |
| URL | https://www.nonstopexpress.com/… | 2023-10-27 | 2023-10-27 |
| URL | https://www.droof.kr/Board/html… | 2023-10-27 | 2023-10-27 |
| URL | https://kscmfs.or.kr/member/han… | 2023-10-27 | 2023-10-27 |
| URL | http://www.friendmc.com/upload/… | 2023-10-27 | 2023-10-27 |
| URL | https://mainbiz.or.kr/include/c… | 2023-10-27 | 2023-10-27 |
| URL | https://safemotors.co.kr/daumed… | 2023-10-27 | 2023-10-27 |
| URL | https://www.hanlasangjo.com/edi… | 2023-10-27 | 2023-10-27 |
| URL | http://yoohannet.kr/min/tmp/pro… | 2023-10-27 | 2023-10-27 |
| URL | https://yoohannet.kr/min/tmp/pr… | 2023-10-27 | 2023-10-27 |
| DOMAIN | theorigin.co.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | warevalley.com | 2023-10-27 | 2023-10-27 |
| DOMAIN | pediatrics.or.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | safemotors.co.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | samwoosystem.co.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | admin.esangedu.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | api.shw.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | hicar.kalo.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | hspje.com | 2023-10-27 | 2023-10-27 |
| DOMAIN | kstr.radiology.or.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | ictm.or.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | new-q-cells.com | 2023-10-27 | 2023-10-27 |
| DOMAIN | vnfmal2022.com | 2023-10-27 | 2023-10-27 |
| DOMAIN | little-pet.com | 2023-10-27 | 2023-10-27 |
| DOMAIN | pms.nninc.co.kr | 2023-10-27 | 2023-10-27 |
| DOMAIN | ucware.net | 2023-10-27 | 2023-10-27 |
| DOMAIN | swt-keystonevalve.com | 2023-06-08 | 2023-10-27 |