Analysis of attack activities of Moonstone sleet a division of APT-C-26 (Lazarus) group
2025-02-16 • Blue Eye •
https://blu3eye.gitbook.io/malware-insight/moonstone-sleet-trojaned-putty
The write-up analyzes Moonstone Sleet activity involving a trojanized PuTTY installer delivered through platforms such as LinkedIn and Telegram. The installer checks the victim-entered password against a hardcoded value before decrypting the next-stage payload with HC-256, decompressing it, and mapping a DLL in memory. The installer module drops SplitLoader components as usrgroup.dat and thumbcache_512.db, sets persistence through a scheduled task and an HKCU Run key, and requires specific arguments, including the magic string "4701", to decrypt and execute later stages. The source frames the case as evidence of Moonstone Sleet using trojanized software, uncommon HC-256 encryption, and argument-gated loader execution in Lazarus-linked operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d65e05c961107c787310c4f369034b0… | 2025-02-16 | 2025-02-16 |
| HASH | fcb687685f71615c83e9af26087e603… | 2025-02-16 | 2025-02-16 |
| HASH | 00433ebf3b21c1c055d4ab8a599d3e8… | 2025-02-16 | 2025-02-16 |
| HASH | cf1947c7af6581f4a66460ae6d14dc2f | 2025-02-16 | 2025-02-16 |
| HASH | f59035192098e44b86c4648a0de4078… | 2024-05-28 | 2025-02-16 |
| HASH | 63fb47c3b4693409ebadf8a5179141a… | 2024-02-21 | 2025-02-16 |