Analysis of attack activities of Moonstone sleet a division of APT-C-26 (Lazarus) group

2025-02-16 Blue Eye

https://blu3eye.gitbook.io/malware-insight/moonstone-sleet-trojaned-putty

Thumbnail for Analysis of attack activities of Moonstone sleet a division of APT-C-26 (Lazarus) group

The write-up analyzes Moonstone Sleet activity involving a trojanized PuTTY installer delivered through platforms such as LinkedIn and Telegram. The installer checks the victim-entered password against a hardcoded value before decrypting the next-stage payload with HC-256, decompressing it, and mapping a DLL in memory. The installer module drops SplitLoader components as usrgroup.dat and thumbcache_512.db, sets persistence through a scheduled task and an HKCU Run key, and requires specific arguments, including the magic string "4701", to decrypt and execute later stages. The source frames the case as evidence of Moonstone Sleet using trojanized software, uncommon HC-256 encryption, and argument-gated loader execution in Lazarus-linked operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d65e05c961107c787310c4f369034b0… 2025-02-16 2025-02-16
HASH fcb687685f71615c83e9af26087e603… 2025-02-16 2025-02-16
HASH 00433ebf3b21c1c055d4ab8a599d3e8… 2025-02-16 2025-02-16
HASH cf1947c7af6581f4a66460ae6d14dc2f 2025-02-16 2025-02-16
HASH f59035192098e44b86c4648a0de4078… 2024-05-28 2025-02-16
HASH 63fb47c3b4693409ebadf8a5179141a… 2024-02-21 2025-02-16

Related Actors

Related Reports

« Back