Analysis of Lazarus malware abusing Non-ActiveX Module in South Korea

2021-07-08 S2W

https://medium.com/s2wlab/analysis-of-lazarus-malware-abusing-non-activex-module-in-south-korea-7d52b9539c12

Thumbnail for Analysis of Lazarus malware abusing Non-ActiveX Module in South Korea

S2W analyzes a Lazarus-linked signed DLL disguised as the open-source Notepad++ ComparePlus plugin and apparently tailored to systems with a South Korean Non-ActiveX security component installed. The malware checked for INITECH/INISAFE Web EX Client files and SCSKAppLink.dll before loading itself through comp.exe, using DLL injection to force execution. Its final behavior was to download an additional payload from compromised Korean web infrastructure, decrypt it with RC5, and execute it in memory; observed URLs included grandgolf.co.kr, namchuncheon.co.kr, and kdone.co.kr paths with product_field=racket. The report ties the sample to Lazarus through similarities in string-decoding logic and the group's recurring use of normal-file masquerading, signed components, and domestic Korean distribution sites.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b3a8c88297daecdb9b0ac54a3c107797 2021-07-08 2023-04-12
HASH a881c9f40c1a5be3919cafb2ebe2bb5… 2021-07-08 2022-04-14
HASH 61367c3a1d4c9ccaee568157bc4cf2f… 2021-07-08 2021-07-08
HASH 98151ba9f3e0a55bba16c58428b3a178 2021-07-08 2021-07-08
HASH 46660f562fe01b5df0e1ac03dd44b4c… 2021-07-08 2021-07-08

Related Actors

Related Reports

« Back